Privacy and local processing
Keep assessment information under organisational control.
The planned applications use local browser processing by default. This page distinguishes the public product website from the future assessment tools.
Public product pages
The pages in this package are static. They contain no assessment database, user account, payment system, analytics script or advertising tracker. A live DigiData deployment may use the site's general hosting logs and website privacy controls, which the main DigiData privacy notice will govern.
Planned assessment applications
The design objective is to process answers and evidence in the user's browser. The application should not transmit project content to DigiData merely because the user completes an assessment.
- Optional local save through IndexedDB.
- Local evidence attachments where the browser permits them.
- JSON export and import for user-controlled transfer.
- Browser print or save-to-PDF for the reasoning record.
- Optional passphrase encryption for exported project files, subject to security review.
No personal-data requirement by design
PARITY and MIRROR can usually operate through journey, cohort, system and variant evidence without entering identifiable consumer records. MOMENT should use synthetic or cohort-level scenarios by default and should not collect real vulnerability data merely to complete the method.
User responsibility
An organisation must decide what information it may lawfully enter, attach, export and retain. Local processing does not remove obligations concerning lawful basis, minimisation, security, access control, retention, confidentiality or records management.
Browser storage boundary
Browser storage can persist on the device and may be accessible to other users of the same browser profile. Clearing browser data, changing device or using private browsing may delete the saved project. The production release must explain these behaviours clearly.
Attachments and exported files
Project files and reports leave the browser only when the user saves, transfers, uploads or shares them. The user must protect those files through approved organisational storage, access controls and retention rules.
No automated model processing
The core methods do not require assessment content to pass through a generative model. Any future optional writing assistance must remain separate, transparent and user-controlled, with explicit information about processing location and provider terms.
Security work still required
Local-first architecture reduces central data collection but does not guarantee security. Before production release, the applications require threat modelling, dependency review, content-security policy, secure file handling, encryption review, browser compatibility testing and clear incident procedures.
The public pages describe the intended architecture. They do not yet provide a production security assurance or data-protection guarantee.