LSSCO / Security & data handling

Public-site data, demonstrations and client records are treated as separate environments.

This page states the intended handling model for the website and LSSCO engagements. Project-specific controls are confirmed in the contract, data schedule and delivery design before live client records are collected.

Three data zones

Do not mix a public demonstration with a live client environment.

The separation is a core control, not a marketing footnote.

01 / PUBLIC SITE

Published information.

Marketing copy, sample methodology and synthetic demonstration records. No live credentials, clients, properties or technical configurations belong here.

02 / ENQUIRY

Minimal contact information.

Name, organization, contact details, broad service interest and a high-level problem description. Sensitive system information should not be submitted through the public form.

03 / CLIENT DELIVERY

Defined project environment.

Records, access roles, retention, recipients, providers and technical evidence are agreed for the engagement before collection begins.

Website safeguards

Minimal collection and no non-essential tracking.

The public site uses static assets, a synthetic demonstration and restrictive response headers. It is not used as a repository for live client records, credentials or technical evidence.

Encrypted transport.

The canonical website is configured for HTTPS and HTTP Strict Transport Security.

Restrictive headers.

Content Security Policy, frame restrictions, referrer control and MIME-sniffing protection are included.

Static demonstration.

The sample control record runs in the browser. Its handover checklist uses local browser storage only.

No non-essential tracking.

No third-party analytics, session replay, advertising tags or non-essential cookie code are included.

Client engagement controls

Agreed before live data is processed.

The exact position depends on scope, location, client systems, appointed providers and contractual roles.

PURPOSE

Defined collection purpose.

Each record category must support an agreed operating, reporting, evidence or handover need.

ACCESS

Named roles and least access.

Owner, LSSCO operator, adviser, contractor, provider and read-only recipient permissions are documented.

TRANSFER

Approved recipients.

Reports and evidence are distributed only through the agreed route and to the approved audience.

RETENTION

Project-specific schedule.

Retention and deletion are set according to purpose, contractual need, law and professional-record requirements.

INCIDENT

Notification and containment.

The client contact, LSSCO lead, technical provider and decision route are set before a live incident occurs.

EXIT

Handover or secure closure.

Client exports, access removal, open records, retained copies and destruction decisions are documented.

Technical evidence language

Recorded, not invented.

Where a control depends on logs, hashes, exports, alerts, configuration records or test results, the record identifies the source platform or appointed provider. LSSCO does not describe a feature as active merely because it appears in a methodology.

Important submission rule

Do not send secrets through the enquiry form.

Do not submit passwords, API keys, security architecture, patient information, employee files, incident evidence or detailed system vulnerabilities. Use the form only to arrange a controlled discussion.