Access control
Named accounts, roles, least privilege, and removal of access when a person leaves a project.
Capability
We treat security as part of how a system is built and run — not as a slogan. The focus is defensive: who can see data, how it moves, and how work continues after a failure.
This is the work we do on SAWE products and on partner systems: accounts, permissions, encrypted connections, backups, and careful handling of health and survey records.
What we do
Named accounts, roles, least privilege, and removal of access when a person leaves a project.
HTTPS/TLS on websites and APIs so passwords and records are not sent in clear text.
Database permissions, hashed passwords, and restricted folders for identifiable files.
Scheduled copies and a tested restore path so a disk failure or mistake is not the end of the dataset.
Audit trails for logins and sensitive changes, and a process for reporting bugs and incidents.
Separation of identifiers, limited exports, and collection tools (such as REDCap) configured with project user rights.
Tools and practices we use
Tell us the dataset, the field setting, and the decision the work must support. We will propose a concrete stack and a delivery path.
Contact SAWE