Consent & Privacy Service  ·  View 20 of 22  ·  Assurance

Trust Zones

Five zones, and the separation the whole security argument rests on sitting between two of them.

Editable source SVG draw.io All views
Internet Subject device Processor 60 Supervisory authority Perimeter CloudFront + WAF API Gateway Subject authn + step-up Rate & anomaly scoring Application — regional Capture Decision Case orchestrator Target adapters Data — separately authorised Consent ledger Per-subject keys Identity index crown jewels Evidence — write-once Audit store Object Lock TLS verified subject step-up proof purpose-scoped case-bound shred append only signed instruction Trust Zones — What Crosses, and What Is Checked Person or role External / third party Interface / broker Security / platform Application we own Data store synchronous event / async The decision path and the identity index are authorised separately. An attacker holding decision credentials learns what a subject refused, not who they are elsewhere. v 1.0 · owner Security & Identity Architecture

Decisions

  • The decision path and the identity index are authorised separately. An attacker holding decision credentials learns what a subject refused; they do not learn who that subject is anywhere else.
  • Access to the identity index is case-bound: it answers for the identifiers an open case needs and logs every record it returns. There is no standing read.
  • The evidence zone is write-once and reached only by append. Nothing in the application zone holds a credential that can modify or delete an audit record.

The platform as an attack surface

  • An attacker who can forge a grant has legalised processing — a quieter and more valuable outcome than stealing data, and the reason surface and actor are recorded on every entry and scored for anomalies.
  • An attacker who can read the ledger learns what each person refused, which is itself sensitive. The ledger is purpose-scoped, not broadly readable, even inside the platform.
  • The rights surfaces are rate-limited and anomaly-scored: an open unauthenticated erasure endpoint is a denial-of-service weapon aimed at the company's own users.

Assumptions

  • Two-person approval for a purpose version change, a bulk import, a retention extension, or any administrative override of a consent state.
  • Agent access is just-in-time, case-bound and time-boxed to 30 minutes.