01
Identity & Access
Restricted operations require verified identity, strong authentication, role authorization and periodic access review.
Platform Security
IAARM separates public information from restricted operations and applies layered safeguards to identity, authorization, sensitive evidence, workflow integrity, monitoring and recovery.

Security Controls

01
Restricted operations require verified identity, strong authentication, role authorization and periodic access review.
02
Permissions are scoped to role, organization and function; high-risk actions require separation and, where applicable, independent approval.
03
Sensitive submissions are classified, access-controlled, encrypted and subjected to file-validation and review controls.
04
Material access, workflow, decision, publication and security events are recorded for investigation and oversight.
05
Rate limits, method restrictions, request validation and security monitoring protect public and restricted services.
06
Backup, recovery, incident response and controlled change practices support availability and integrity.
Public Information
The public register contains only fields approved for public verification. Application evidence, internal assessment records, security configuration and other restricted information remain access-controlled and are not included in public content.

Responsible Reporting
Do not access, alter, retain or disclose data beyond what is necessary to describe a good-faith finding. Provide the affected URL, observed behavior, reproduction conditions and potential impact without including sensitive personal or certification evidence.
