Compliance and privacy

How this site handles information

This page is maintained by the NCC Organizational AI project team to answer common security and privacy questions about this website. It describes current practices for this conceptual design site; it is not a certification or an independent audit statement.

Scope

What this website is, and what it is not

The public pages present a conceptual operating model for design and stakeholder discussion. They contain no case data, no reports, no victim or offender information, and no operational records.

The interactive operating map is a design artefact shared only with named, invited participants. It illustrates structure and relationships; it is not a live system and holds no institutional case content.

  • No case or child-protection data

    No CyberTipline referrals, case files, personal case narratives or investigative material are stored, processed or displayed by this website.

  • No public access to the map

    The operating map is served only to signed-in invited users through an authorised server request. It is not published as a public file and is excluded from indexing.

  • Design artefact only

    Nothing on this site replaces existing NCC systems, records management, or the CyberTipline management software; the model is designed to integrate, not replace.

Personal data

What we collect and why

Access is invitation-only. The only personal data required is the work email address of an invited participant, used solely to authenticate that person.

  • Email address of invited participants, held on an allowlist and used to issue one-time sign-in links.
  • Invitation metadata: who invited the account, the assigned role (admin or member), and the invitation date.
  • Authentication session records created by the managed authentication service when a participant signs in.
  • No marketing analytics, advertising trackers, third-party profiling or cross-site cookies are used.
  • Cookies and local session storage are strictly necessary: they keep an invited user signed in and nothing more.

Safeguards

Technical and organisational measures

  • Authentication and authorisation

    Sign-in uses one-time email links against an allowlist; there is no shared password and no public self-registration. Administrative screens require an explicit admin role checked on the server.

  • Server-side gating

    Protected content is retrieved through authenticated server functions with row-level database policies, so restricted material is never bundled into public files or client assets.

  • Transport and browser hardening

    HTTPS is enforced with strict transport security, and responses carry a Content Security Policy plus nosniff, framing, referrer, cross-origin isolation and permissions-policy headers.

  • Indexing and leakage controls

    Invitation-only routes send noindex/nofollow robots headers, are disallowed in robots.txt, are excluded from the sitemap, and are served with no-store caching so shared proxies retain nothing.

  • Least-privilege access

    Membership is managed by the project administrator; access can be revoked at any time, immediately removing the ability to sign in or open the map.

  • Retention and deletion

    Invitation and account records are kept only while a participant needs access to the design review, and are removed on request or when access is revoked.

Governance alignment

Regulatory context

The operating model is designed to support—not substitute for—NCC's statutory and policy obligations. The following statements describe design intent for the model and handling practices for this website.

  • RA 11930 (Anti-OSAEC and Anti-CSAEM Act): compliance and reporting requirements are represented as first-class obligations in the model, with owners, deadlines and evidence.
  • Data Privacy Act of 2012 (RA 10173): personal data on this site is limited to invited participants' work email addresses, processed for the legitimate purpose of controlling access.
  • Authority and provenance: the model records who contributed what, under which mandate, so that any future implementation remains auditable.
  • Shared responsibility: the hosting platform provides infrastructure, transport security and managed authentication; the NCC project team is responsible for who is invited and what is published here.

Contact

Privacy requests and security reports

To request removal of your access, ask what information is held about you, or report a suspected security issue with this website, contact the project administrator at george@ayla-app.com.

Please do not send case material, personal data about children, or investigative content to this address or through this website; those belong in NCC's authorised systems.