Platform Security

Protecting IAARM services and confidential records.

IAARM separates public information from restricted operations and applies layered safeguards to identity, authorization, sensitive evidence, workflow integrity, monitoring and recovery.

Security Controls

How IAARM protects systems and information.

01

Identity & Access

Restricted operations require verified identity, strong authentication, role authorization and periodic access review.

02

Least Privilege

Permissions are scoped to role, organization and function; high-risk actions require separation and, where applicable, independent approval.

03

Evidence Protection

Sensitive submissions are classified, access-controlled, encrypted and subjected to file-validation and review controls.

04

Accountability

Material access, workflow, decision, publication and security events are recorded for investigation and oversight.

05

Abuse Resistance

Rate limits, method restrictions, request validation and security monitoring protect public and restricted services.

06

Continuity

Backup, recovery, incident response and controlled change practices support availability and integrity.

Public Information

Restricted evidence is kept separate from public content.

The public register contains only fields approved for public verification. Application evidence, internal assessment records, security configuration and other restricted information remain access-controlled and are not included in public content.

Responsible Reporting

Report a suspected vulnerability privately.

Do not access, alter, retain or disclose data beyond what is necessary to describe a good-faith finding. Provide the affected URL, observed behavior, reproduction conditions and potential impact without including sensitive personal or certification evidence.

Security contact