Consent & Privacy Service · View 20 of 22 · Assurance
Decisions
- The decision path and the identity index are authorised separately. An attacker holding decision credentials learns what a subject refused; they do not learn who that subject is anywhere else.
- Access to the identity index is case-bound: it answers for the identifiers an open case needs and logs every record it returns. There is no standing read.
- The evidence zone is write-once and reached only by append. Nothing in the application zone holds a credential that can modify or delete an audit record.
The platform as an attack surface
- An attacker who can forge a grant has legalised processing — a quieter and more valuable outcome than stealing data, and the reason surface and actor are recorded on every entry and scored for anomalies.
- An attacker who can read the ledger learns what each person refused, which is itself sensitive. The ledger is purpose-scoped, not broadly readable, even inside the platform.
- The rights surfaces are rate-limited and anomaly-scored: an open unauthenticated erasure endpoint is a denial-of-service weapon aimed at the company's own users.
Assumptions
- Two-person approval for a purpose version change, a bulk import, a retention extension, or any administrative override of a consent state.
- Agent access is just-in-time, case-bound and time-boxed to 30 minutes.