Compliance and privacy
How this site handles information
This page is maintained by the NCC Organizational AI project team to answer common security and privacy questions about this website. It describes current practices for this conceptual design site; it is not a certification or an independent audit statement.
Scope
What this website is, and what it is not
The public pages present a conceptual operating model for design and stakeholder discussion. They contain no case data, no reports, no victim or offender information, and no operational records.
The interactive operating map is a design artefact shared only with named, invited participants. It illustrates structure and relationships; it is not a live system and holds no institutional case content.
No case or child-protection data
No CyberTipline referrals, case files, personal case narratives or investigative material are stored, processed or displayed by this website.
No public access to the map
The operating map is served only to signed-in invited users through an authorised server request. It is not published as a public file and is excluded from indexing.
Design artefact only
Nothing on this site replaces existing NCC systems, records management, or the CyberTipline management software; the model is designed to integrate, not replace.
Personal data
What we collect and why
Access is invitation-only. The only personal data required is the work email address of an invited participant, used solely to authenticate that person.
- Email address of invited participants, held on an allowlist and used to issue one-time sign-in links.
- Invitation metadata: who invited the account, the assigned role (admin or member), and the invitation date.
- Authentication session records created by the managed authentication service when a participant signs in.
- No marketing analytics, advertising trackers, third-party profiling or cross-site cookies are used.
- Cookies and local session storage are strictly necessary: they keep an invited user signed in and nothing more.
Safeguards
Technical and organisational measures
Authentication and authorisation
Sign-in uses one-time email links against an allowlist; there is no shared password and no public self-registration. Administrative screens require an explicit admin role checked on the server.
Server-side gating
Protected content is retrieved through authenticated server functions with row-level database policies, so restricted material is never bundled into public files or client assets.
Transport and browser hardening
HTTPS is enforced with strict transport security, and responses carry a Content Security Policy plus nosniff, framing, referrer, cross-origin isolation and permissions-policy headers.
Indexing and leakage controls
Invitation-only routes send noindex/nofollow robots headers, are disallowed in robots.txt, are excluded from the sitemap, and are served with no-store caching so shared proxies retain nothing.
Least-privilege access
Membership is managed by the project administrator; access can be revoked at any time, immediately removing the ability to sign in or open the map.
Retention and deletion
Invitation and account records are kept only while a participant needs access to the design review, and are removed on request or when access is revoked.
Governance alignment
Regulatory context
The operating model is designed to support—not substitute for—NCC's statutory and policy obligations. The following statements describe design intent for the model and handling practices for this website.
- RA 11930 (Anti-OSAEC and Anti-CSAEM Act): compliance and reporting requirements are represented as first-class obligations in the model, with owners, deadlines and evidence.
- Data Privacy Act of 2012 (RA 10173): personal data on this site is limited to invited participants' work email addresses, processed for the legitimate purpose of controlling access.
- Authority and provenance: the model records who contributed what, under which mandate, so that any future implementation remains auditable.
- Shared responsibility: the hosting platform provides infrastructure, transport security and managed authentication; the NCC project team is responsible for who is invited and what is published here.
Contact
Privacy requests and security reports
To request removal of your access, ask what information is held about you, or report a suspected security issue with this website, contact the project administrator at george@ayla-app.com.
Please do not send case material, personal data about children, or investigative content to this address or through this website; those belong in NCC's authorised systems.