Security & data protection

Trust & Data Protection

Safety observations are sensitive. They describe people, sites, contractors and mistakes. Here is exactly how that information is separated, protected and used inside Safety Campaign Hub.

Tenant isolation by default

Every observation, action, campaign and analytic record is stamped with your organisation ID. Database row-level security enforces that boundary on every read and write, so one organisation can never see or modify another's data — even if a request is crafted by hand.

Role-based access

Owners, admins, managers, QHSSE professionals, action owners and viewers each see only what their role permits. Role assignments are stored separately from user profiles so they cannot be escalated from the client.

Anonymous and confidential reporting

Reporters can submit named, confidential or fully anonymous observations. Anonymous reports store no reporter identity at all, and confidential reports restrict the reporter's name to reviewers. Reporting mode is explained plainly at the point of capture.

Photos and evidence

Images and closure evidence are stored in access-controlled buckets scoped to your organisation. Reporters are reminded not to capture faces, personal documents or identifiable details before uploading.

Contractor access is scoped to one action

External action owners never receive an account into your workspace. They reach a single assigned action through a tokenised link with expiry and revocation — no observations, no analytics, no other organisation data.

Responsible AI processing

AI is used to translate, summarise, classify risk and draft campaign content. It suggests — a human confirms. AI classifications are labelled as suggestions and require reviewer confirmation before they affect reporting. Your data is not used to train third-party models.

Data residency, backup and export

Data is held in managed, encrypted cloud infrastructure with automated backups. You can export observations, actions and campaign content at any time, and request deletion of your organisation's data when you leave.

Encryption in transit and at rest

All traffic runs over TLS, and data is encrypted at rest by the underlying platform. Secrets and API keys are held in a managed secret store and never exposed to the browser.

What we ask of you

  • Keep observation descriptions factual and avoid naming individuals — the platform is designed to improve systems, not to attribute blame.
  • Review AI suggestions before acting on them. Risk levels, SIF potential and recommended actions are drafts until a competent person confirms them.
  • Remove contractor access when an action is closed, and keep role assignments current as people change jobs.

Read the full Privacy Policy and Terms of Service. For a security questionnaire, DPA or penetration-test summary, email info@safetycampaignhub.com.