Security & incident response

Devil-Guard uses technical and organisational controls intended to reduce unauthorised access, misuse and unnecessary retention. No internet service can promise zero risk, so incident response is part of the privacy program.

Protected credentials

Passwords are stored as password hashes; personal client/enforcer tokens are stored as one-way hashes where designed; sensitive stored identifiers use the configured application data-encryption key.

Access control

Admin, Council, Server Host and client capabilities are separated by role. Sensitive evidence attachments are restricted and downloads are audited.

Scoped server enforcement

Devil-Guard Server manages only Devil-Guard-owned HawkSync records and scoped DFBHD firewall rules instead of broad unrelated firewall access.

Contain and assess

If a suspected breach occurs, the response should contain the incident, preserve necessary audit information, assess the affected data/people, remediate the cause and document the decision-making.

Australian NDB scheme

Where the Notifiable Data Breaches scheme applies and an eligible breach is likely to cause serious harm that cannot be prevented by remedial action, affected people and the OAIC are notified as required.

GDPR breach duties

Where GDPR applies, a reportable personal-data breach is notified to the competent supervisory authority without undue delay and, where feasible, within 72 hours of awareness; high-risk breaches are communicated to affected people as required.