EvidenceGate
Documents
/
DOC-007
Saved, v0.6
Export
Save version
Governance
Draft
In review
Approved
Hemnaath
Sai
Both
Tenant isolation, protected-health-information controls, model isolation, audit events, retention, and incident readiness.
Markdown
H2
List
Use # headings, - lists, and plain text. Every save creates a revision.
# Security, Privacy, and Audit Controls ## Data classification Pre-authorization packets contain protected health, identity, financial, and policy information. All case content is confidential. EvidenceGate metadata is confidential unless explicitly aggregated and de-identified. ## Access - Tenant isolation is enforced in every service and query. - Hospital operator, reviewer, policy author, rule approver, auditor, and administrator are separate roles. - Least privilege and workload identity replace shared service credentials. - Material exports and policy publication require step-up authentication. ## Encryption and keys - TLS for all service and partner connections. - Managed encryption at rest for databases, objects, queues, backups, and search indexes. - Tenant-aware key strategy for enterprise deployments. - Key rotation and access logging. ## Model isolation - Send only required pages or regions. - Disable provider training and retention where contractually available. - Do not place protected health information in prompts used for testing or observability. - Record provider, model, region, configuration, prompt version, and response hash. - Provide a private or customer-hosted model path for regulated buyers that require it. ## Logging Application logs contain identifiers and event codes, not document text, medical facts, or snippets. Sensitive troubleshooting access is time-limited and audited. ## Audit events Capture case creation, file upload, document classification, extraction run, fact correction, rule selection, rule execution, packet generation, review action, override, export, policy publication, authentication change, and administrative access. ## Retention Retention and deletion are tenant-configurable within legal and contractual constraints. Deletion requests cover operational stores, objects, search indexes, caches, and scheduled backup expiry. Audit retention is documented separately from document retention. ## Incident readiness - Security contacts and severity levels. - Detection and containment procedures. - Partner notification workflow. - Evidence preservation. - Credential and key rotation. - Recovery and post-incident review. ## Production gate Threat model, penetration test, dependency scanning, backup restoration, access review, data-flow review, and incident tabletop must be complete before live protected health information is processed.