SECURITY
Built to be inspected by procurement.
Architecture, data handling, access and the current assurance position, stated plainly.
Operating model.
The platform is architected to operate within the client's own environment. External cloud AI services are not a dependency of the design — the platform can run without them, and that is deliberate.
For a programme handling commercially sensitive cost records, operating model is a security question procurement asks early, and "local by default" is a cleaner answer than a data-processing addendum.
Access and authority.
The access model is designed around named identity and explicit authority. Actions are designed to be attributed to that identity and recorded. Permissions are designed to be granted explicitly against the authority roster; no permission is assumed by default.
Audit trail.
The platform is designed so that every governed act is written to an immutable audit trail. This is designed to cover access events, gate decisions, finding approvals and report issuances — with the identity of the person, the timestamp and the action.
The platform is designed so that the evidence store is append-only and content-addressed, preventing retrospective alteration of the trail and enabling a forensic review of what happened in an audit to be reconstructed from the record alone.
Reporting a vulnerability.
If you believe you have found a security issue, email intelligence@westheathci.com. Security reports are reviewed promptly and prioritised according to their nature and severity. There is no bounty programme.
Request a briefing
A working conversation about how any of these applies to your programme.