Security & Data

Built to protect sensitive programme information.

ERP assurance can involve commercially sensitive programme data, supplier performance, delivery weaknesses, governance failures and executive decision-making. PHAT is therefore being designed around a simple principle: to minimise collection, exposure and retention — and make necessary access explicit and bounded.

Security by design, not by disclaimer

PHAT does not need access to your programme repository.

The core diagnostic is designed to work with the minimum information required to support a defensible assurance conclusion, using information provided by you rather than requiring open access to your programme systems or repositories.

Lower-data assurance. Where appropriate, the assessor can record the evidence source reviewed, relevant finding, assessment conclusion and evidence confidence while the underlying document remains within the client's existing controlled repository.
01 / MINIMUM NECESSARY DATA

Capture what matters. Not another copy of everything.

PHAT is not intended to become a second document-management system. Evidence can remain where it already lives while the assurance record captures what is necessary to support the conclusion.

03 / ENGAGEMENT SEGREGATION

Separate clients. Separate programmes.

Each client and programme engagement is treated as a separate assurance environment, segregating its information from other clients and programmes.

Partner organisation→Client→Programme→Review period→Authorised users
04 / ROLE-BASED ACCESS

Access appropriate to the role.

Within each engagement, access is controlled by user role so that users can see and act only on the information and functionality appropriate to their responsibilities.

05 / DELIBERATE RETENTION

Client data has a PHAT shelf-life.

Client data will be retained only for as long as necessary, with retention requirements agreed for each engagement. Access will be removed when an engagement ends, with controlled deletion, documented treatment of backups, and preservation only where contractually or legally required.

02 / AI-INDEPENDENT CORE

PHAT Assurance is not AI dependent.

The core assessment, scoring and diagnostic logic operates from structured assessment data and expert reviewer judgement. AI is not required to determine the PHAT score, identify the programme's diagnostic position or reach the assurance conclusion.

PHAT Assurance does not require client information to be processed by AI. Where client policy prohibits AI processing, the assurance can be conducted without client programme information being submitted to an AI model.

If AI-assisted capabilities are introduced, they will support selected reviewer activities rather than replace the core diagnostic methodology or expert assurance judgement. Their use will be subject to the client's agreed information-handling requirements.

Production security requirements

PHAT production security controls.

PHAT is designed to operate within defined security requirements across all production client and programme environments.

Strong authenticationEnterprise identity and multi-factor authentication.
EncryptionProtection of production data in transit and at rest.
Least privilegeAccess limited to the minimum necessary for each user's role.
AuditabilityLogging of significant access, administrative and assessment activity.
Secure configurationAdministrative credentials and application secrets managed outside the application codebase.
Environment separationDevelopment and test environments separated from live client data.
AI & client data

No hidden use of client information.

Where AI-assisted features are permitted, their purpose and use will be explicit. Only information necessary for the specific function will be processed, client information will not be used to train public or shared models, and AI-assisted output will remain subject to expert reviewer judgement.

Where client policy prohibits AI processing, PHAT Assurance can be conducted without client programme information being submitted to an AI model.

Hosting & subprocessors

Know where the data goes.

Before client information is processed within PHAT, its hosting location, applicable data residency, backup arrangements, relevant subprocessors and the services authorised to access that information will be defined and available to the client.

The objective is a transparent data path rather than an opaque technology supply chain.

The same principle as the assurance methodology

Do not assume. Evidence it.

PHAT is built to give clients confidence not only in the conclusions it produces, but also in how their information is handled in reaching those conclusions.

Minimum dataControlled accessSegregated engagementsOptional AIExplicit retentionEvidenced controls
Client security requirements

Have a security, data-residency or AI-policy requirement?

Discuss it before the engagement. PHAT's aim is to make the information-handling model explicit rather than ask clients to infer it.