and acknowledge that we store your professional profile data to operate this platform.
Cookies set by this platform
session
Your login session, stored server-side (database). Expires after 2 hours of inactivity, or 30 days if you tick "Keep me signed in".
XSRF-TOKEN
Cross-site request forgery protection. Required for all form submissions. Set on every page load, expires with your browser session.
remember_web_*
Set only if you tick "Keep me signed in". A cryptographically signed token; expires in 30 days. Clearing your cookies removes it immediately.
Data we store about you
Account
Your name, work email address, and hashed password (bcrypt, never stored in plain text).
Profile
Job title, department, and phone number — only what you choose to fill in under My Profile.
Activity
Audit actions (evidence uploads, status changes, findings) — required to maintain the compliance audit trail this platform is built to provide.
Security logs
Login timestamps and IP addresses (pseudonymised via one-way hash in logs — the raw IP is not retained). Required for intrusion detection and DPDP Act 2023 compliance.
We do not use advertising, tracking, or analytics cookies. Cloudflare is used for DDoS protection and TLS termination — see Cloudflare's privacy policy for their data handling.
Read our full Privacy Policy