Access and identity
Who needs access, which roles can see each record, how private preparation is handled, and what authentication your agency requires.
Review records can contain sensitive information. Security and information governance belong in the conversation from the outset.
This page sets out topics for due diligence. It is not a statement of certification or a completed security specification.
Who needs access, which roles can see each record, how private preparation is handled, and what authentication your agency requires.
Where data would be stored, who would process it, and the arrangements for encryption, backup and recovery.
How long records and private notes need to be retained, how deletion would work, and how your agency would retrieve its data.
What attribution, version history and audit evidence your agency needs, including the separation of recommendation and decision.
The agreements, data-flow information, subprocessor details and assessment material your team would need to review.
Any proposed AI assistance should have an explicit scope. Our intended boundary is support for administration and preparation, with suitability assessments, recommendations and decisions remaining with professionals.
Tell us which security and governance requirements matter to your organisation.
Current capabilities and available documentation should be confirmed directly with Arcaja Tech before sharing live case information or agreeing a pilot.
Book a 30-minute workflow review