Platform Security
OCBDC is designed as a protected project-planning workspace. Security is a continuing operational practice, not a one-time certification.
Security architecture
- Encrypted HTTPS connections;
- Server-side authentication and authorization;
- Institution, project, role, and assignment-based access controls;
- Rate limiting and request validation for sensitive actions;
- Credential hashing rather than readable password storage;
- Audit activity for key project and administrative events;
- Backups and controlled report-version workflows; and
- Software maintenance, malware scanning, and integrity monitoring.
Shared responsibility
Institutions must configure roles carefully, remove access promptly, protect invite links, review exports, use unique passwords, and avoid submitting regulated or unnecessary personal information. Users should report suspicious activity immediately.
Reporting a security concern
Email info@ocbdc.com with “Security report” in the subject. Do not include exploit code, passwords, patient information, or confidential project files in the first message. We will provide a safe follow-up channel if needed.
No unsupported compliance claims
This page does not state that the Platform is certified under a particular standard or suitable for regulated health data. Institution-specific security commitments belong in the applicable written agreement.