Skip to content
Architects

Platform Security

Security architecture

  • Encrypted HTTPS connections;
  • Server-side authentication and authorization;
  • Institution, project, role, and assignment-based access controls;
  • Rate limiting and request validation for sensitive actions;
  • Credential hashing rather than readable password storage;
  • Audit activity for key project and administrative events;
  • Backups and controlled report-version workflows; and
  • Software maintenance, malware scanning, and integrity monitoring.

Shared responsibility

Institutions must configure roles carefully, remove access promptly, protect invite links, review exports, use unique passwords, and avoid submitting regulated or unnecessary personal information. Users should report suspicious activity immediately.

Reporting a security concern

Email info@ocbdc.com with “Security report” in the subject. Do not include exploit code, passwords, patient information, or confidential project files in the first message. We will provide a safe follow-up channel if needed.

No unsupported compliance claims

This page does not state that the Platform is certified under a particular standard or suitable for regulated health data. Institution-specific security commitments belong in the applicable written agreement.