Security and data

The architecture is the promise.

Policies can be changed. Separation that is built into the system cannot be undone by a decision. Here is what the system does not permit, whoever asks.

Role separation, enforced in the backend.

The central operator cannot see recipients

Phone numbers, customer references and recipient lists are not available to the central panel. Not hidden in the interface — not served by the backend at all. Central operations work from summaries.

An institution sees only its own traffic

An institution can see the outcome of the messages it sent. It cannot see a person’s other institutions, and the person’s phone number is not exposed to it.

Location is emergency-only

Shared while an SOS is active, with the guardians the person selected. Not before it starts, not after it ends.

Every action is logged

An append-only audit record of who did what and when — the same record that makes proof of service possible in the first place.

Legal basis

UK GDPR, and a short answer to the obvious question.

ADORASEC Ltd is registered in England and Wales and operates under the UK GDPR and the Data Protection Act 2018. Data is processed in the United Kingdom and the European Economic Area.

Where an institution uses ADORASEC to reach its own residents or customers, that institution is the controller and we are the processor. The terms say so, and our architecture is built so that we could not act otherwise.

We do not sell data, we do not profile recipients, and we do not read message content for any purpose other than delivering it.

“Why should we believe you?”

You should not, on our word. That is why the separation is architectural rather than contractual, why the audit record exists, and why we publish our underlying research including the parts that do not flatter us.

We are open to audit, to independent review of the architecture, and to joint working with an institution’s own security and data protection teams. We would rather be checked than trusted.

Honest status

What is built, and what is not.

Some of what this site describes is running today. Some is in build. We say which, because an institution that finds out later has every right to stop trusting the rest.

Working now

Counter-verified identity · verified sender channel · structured replies with coded answers · delivery, read, reply and failure counts · backend role separation · audit logging · per-person evidence line with exportable certificate.

In build

Consent record export · auditor role · four-eyes authorisation and emergency pause · subject access export.