CND StudioCND Studio

Security

Information security

Our platforms hold the record of decisions for which institutions are accountable. This page describes the measures we take to protect that record, and which decisions remain with the institution.

Last updated:

01Access is based on permissions, not on titles

Which screens a user can open depends on the permissions attached to their role, not on the name of the role. Each institution defines its own authority scheme; the software does not impose an organisational structure.

Ethical separations, such as keeping reviewer and author identities hidden from each other, are enforced by the system rather than left to the attention of individual users.

02Every decision leaves a record that cannot be altered

Who decided what, and when, is kept in an append-only audit trail. The reasons for a decision, for example the rejection of a submission, remain demonstrable years later, including to parties who were not involved at the time.

The audit trail is an integral part of the product and cannot be disabled.

03Documents are stamped and publicly verifiable

Official letters, such as acceptance letters, attendance certificates and invitations, are generated from the institution’s own templates and carry a verification stamp. Anyone holding such a document can confirm its authenticity on a public page without an account.

This approach addresses the risk of forged documents by making the original verifiable rather than by making the document harder to copy.

04Uploaded files are scanned

Files submitted by authors, reviewers and participants are scanned for malware before they reach anyone else in the institution. A publishing or event system receives attachments from external parties by its nature, and file handling is designed accordingly.

05The institution chooses where the data is kept

Nasirus runs as a per-institution installation, hosted on our infrastructure or on the institution’s own servers. In an on-premises deployment the data remains within the institution’s infrastructure. On-premises deployment is a standard option, not a paid exception.

Congirus runs as a cloud platform under the institution’s own account; installation, updates, backups and monitoring are handled by us.

06This website

This website loads no analytics or third-party script before you consent, applies a per-page Content Security Policy with script hashes rather than a blanket allowance, serves its fonts from its own origin, and protects the contact form with an origin check, a honeypot, a rate limit, field validation, header-injection protection and a captcha.

These measures can be checked independently, for example in the network tab of your browser’s developer tools.

07Reporting a vulnerability

If you believe you have found a security issue in this website or in one of our platforms, please write to us with enough detail to reproduce it. We confirm receipt, keep you informed during the investigation and credit you on request. Please do not test against a live customer installation.

Security contact

Vulnerability reports and security questions can be sent to:

[email protected] · +90 (551) 895 82 61