Security

Security Standards

The technical and organisational security controls NFS-Share applies to protect notarial data and prevent fraud.

Last updated: January 2025

Contents

  1. Authentication & Access Control
  2. Data Encryption
  3. Input & Application Security
  4. Session Management
  5. Audit Logging
  6. Fraud Prevention
  7. Infrastructure Security
  8. Incident Response
  9. Responsible Disclosure

1 Authentication & Access Control

Bcrypt Passwords

All passwords are hashed with bcrypt (cost factor 12+). Plaintext passwords are never stored or logged.

Role-Based Access

Granular permission system — staff only see and modify records within their own office and role.

Office Scoping

Every query is scoped to the authenticated user's office ID. Cross-office data access is architecturally blocked.

Biometric Verification

Optional fingerprint verification for high-value transaction confirmation via integrated biometric devices.

2 Data Encryption

3 Input & Application Security

NFS-Share is built following OWASP Top 10 mitigation guidelines.

4 Session Management

5 Audit Logging

NFS-Share maintains an immutable audit trail for all significant actions:

Audit logs cannot be deleted by standard users, including office administrators. Retention: 5 years minimum.

6 Fraud Prevention

NFS-Share includes multiple controls specifically designed to prevent notarial fraud:

7 Infrastructure Security

8 Incident Response

In the event of a confirmed security incident affecting personal data:

To report a suspected security incident: info@nfs-share.com  ·  +250 780 900 039

9 Responsible Disclosure

We welcome responsible security research. If you discover a vulnerability in NFS-Share:

We commit to acknowledging reports within 5 business days and communicating our remediation timeline. We will not pursue legal action against good-faith researchers who follow this policy.