Trust · Security
Each organisation's data, kept apart.
The controls in place today, how they're tested, and the limitations we're still working on.
Controls
What's in place.
Organisation isolation
Organisation, facility, unit and room come from server-side registration — never from audio, AI output or request bodies. Every query is scoped, and automated tests check that one organisation cannot list, read, change or infer another's data.
Role-based access
Admin, supervisor and staff roles with facility and unit scopes, checked on every request and every change.
Device credentials
Single-use enrollment codes that expire after minutes; per-device tokens stored only as hashes; disable, revoke and re-enroll at any time.
Encryption in transit
TLS for devices, apps and browsers. Devices validate the server certificate.
Managed infrastructure
Runs on Cloudflare Workers with managed database, private object storage and queues. Separate environments and secrets for staging and production.
Hardened by default
Rate limits per device and organisation, request size limits, no secrets in client code, AI text escaped in the interface, and audit records for membership, device and settings changes.
Safe retries
Uploads and staff actions are idempotent, so retries after a network failure never duplicate tasks or actions.
Sign-in
Staff sign in through a managed identity provider; permissions are held by AskLight and checked server-side.
Least access internally
AskLight's internal tools show operational data only, and administrative actions are audited.
Known limitations
What we haven't finished.
We'd rather tell you than have you find out.
Reporting a vulnerability
If you believe you've found a security issue in AskLight, please tell us through the contact form and choose “IT / Privacy” as your role. Include enough detail for us to reproduce it, and please don't access data that isn't yours or disrupt the service.
We'll acknowledge your report, keep you updated, and credit you if you'd like. Our security.txt lists the same contact route.
Have a security questionnaire?
Book a conversation and we'll go through it with your team.