Security approach
The controls used to protect RegsUP accounts, regulatory work and service operations.
Updated 4 September 2026Tenant and role isolation
Authenticated requests are checked against the active organization, membership, role and explicit permission. Customer identity and private question data are excluded from expert and member-safe projections.
Source and audit integrity
Official files and structured text retain hashes and source identities. Regulatory analyses, question snapshots, moderation decisions and financial movements use immutable or version-checked records so silent replacement and stale writes fail closed.
Files
Question attachments are private, size-limited and checked for allowed format, structural safety and malware before authorized download. Storage identifiers and original customer identity are not disclosed to experts.
Sessions and recovery
Passwords are stored using one-way password hashing. Sessions can be reviewed and revoked; password changes revoke existing sessions. Recovery and invitation tokens are time-limited and single-purpose.
Reporting a concern
Do not include secrets or customer data in an initial report. Use the RegsUP contact channel with a concise description, affected page and time; the team will arrange a secure evidence channel if needed.