Skip to content

Security

LinkSync holds information about workers and the places and people they visit, and organisations rely on it as evidence. Both need protecting. This page explains, in general terms, how we do it, and how to tell us if you find a problem.

Drafted for review by a solicitor; not yet in force.

Last updated [date]

In short

  • All information is stored in the UK and encrypted, both when stored and when sent.
  • Each organisation’s information is kept separate from every other’s, and that separation is tested before every release.
  • Evidence can’t be altered, by anyone, including us. Every look at or change to personal information is logged.
  • A visit can only be recorded with the worker’s own registered phone, at the real GeoSync. Each GeoSync gives a one-time answer that can’t be copied or replayed.
  • Only the LinkSync staff who need it can see an organisation’s information, and what they do is logged. [How organisations approve support access, once that is built.]
  • Found a security problem? Email security@linksync.co.uk. We won’t take legal action against good-faith research that follows our rules.

1. Our approach

We collect as little as possible, keep it for as short a time as possible, and protect what we keep in layers, so no single failure exposes it. We design LinkSync on the assumption that phones can be tampered with and that people may try to fake a visit, so a visit record never rests on any one thing a phone says.

2. Where data is kept and how it is protected

  • All personal information, and its backups, is stored in the UK. One step of the face check is processed in the European Economic Area, with nothing stored there.
  • Information is encrypted when it is sent over the internet and when it is stored, including backups.
  • Enrolment photos are encrypted with their own keys and kept apart from other data. Live face check images are never stored.
  • The secret keys that make GeoSyncs genuine are kept in a separate, tightly controlled key store. They are never held in our main database or on anyone’s phone.
  • GeoSyncs hold no personal information.
  • Some information is deleted automatically when its time is up, by a check that runs every day, unless an organisation has placed a legal hold: the route recorded while clocked in, 90 days after it was received; the phone readings kept for checking a tap, 90 days after the tap; and an enrolment photo, 30 days after the person leaves or the photo is replaced or withdrawn. [Automatic deletion of other records at the end of their retention period is being built; until then LinkSync does it on request.]

3. Keeping organisations apart

Each organisation’s information is separated at the database itself, not only in our application code, so a mistake in one place can’t expose one organisation’s information to another. Automated tests check this separation for every part of the database. They run on every change, and a change isn’t released if they fail. A GeoSync supplied to one organisation is refused by every other.

4. Who can access what

  • Organisations decide what each of their people can see and do, by role and by the part of the organisation they work in.
  • Built-in safeguards can’t be switched off: nobody can approve their own phone change or the review of their own visit, and sensitive permissions can only be given by people who hold them.
  • Signing in uses a one-time code sent by email, so there are no passwords to steal or reuse. In the app, the sign-in is also tied to the worker’s registered phone, so it can’t be used on any other phone. [Planned before launch: a second sign-in step for web admin users and LinkSync staff.]
  • Sessions are short, and are checked on every request. When someone is removed, their access stops at once.
  • LinkSync staff: access is limited to the staff who need it to run, support and secure LinkSync, and what they do is logged. [Time-limited support access that the organisation approves, recorded in its audit trail, once that is built.] Staff who approve GeoSync installations see only what they need to decide, not who lives there.

5. Evidence you can rely on

  • Each worker has one registered phone, and each phone one worker, across every organisation.
  • When a phone is registered, a security key is created on it that can’t be copied off it. Every tap is signed with that key, and only after the phone’s owner has unlocked it.
  • Each GeoSync gives a one-time answer to a fresh challenge at every tap, so a copied GeoSync, a photographed code or a replayed tap is caught.
  • The phone and the app are checked as genuine when the phone is registered and at every tap.
  • Several independent checks, including where the phone was and whether the GeoSync is where it was fitted, must agree before a visit is Verified. Anything that doesn’t fit is flagged for a person to review.
  • Visit records, check results, reviews and the audit trail are append-only. Nobody using LinkSync can edit or delete them, and only a separate deletion process can remove what has reached the end of its retention period.
  • The rules that decide whether a visit is Verified are the same for every organisation. Changes need two people at LinkSync to approve them, and are versioned and announced.

6. Face checks

Where an organisation switches them on, face checks confirm the vetted worker is the person at the visit. The check confirms the person is live and present, not a photo or a recording, before it compares them with their enrolment photo. The rules are set by LinkSync, not each organisation. Live images are checked straight away and never stored, enrolment photos are never used for anything else, and no face information is ever written to our logs.

7. The audit trail

Every time anyone looks at or changes personal information in LinkSync, it is recorded: who, what, when, and from which part of LinkSync. The record itself holds references, not personal details, and can’t be altered. Organisations can see and search their own audit trail. Failed sign-ins, lockouts and refused access are recorded too.

8. How we build LinkSync

  • Every change is reviewed before release, and must pass automated tests.
  • Changes to security-critical areas, such as encryption, access control, the audit trail and the checks that verify visits, get an extra independent review and their own tests before they go live.
  • We check the software we depend on for known vulnerabilities and keep it up to date.
  • Development and test environments are separate from the live service and never use real personal information.
  • We have LinkSync independently tested for security at least once a year, and after major changes.

9. Running LinkSync

  • LinkSync is hosted with a major cloud provider in the UK, in data centres with strong physical security. [Confirm resilience: designed to keep running if a single data centre fails.]
  • We monitor the service for faults and unusual activity, with automatic alerts. [Confirm out-of-hours cover.]
  • Backups are taken automatically, kept in the UK for 35 days, and we test that we can restore them.
  • If a phone has no signal, the app keeps taps securely and sends them later, so short outages don’t stop workers recording visits.
  • We have a business continuity and disaster recovery plan, and test it at least once a year.

10. If something goes wrong

We have a written plan for security incidents, with clear roles and steps. If a breach affects an organisation’s personal information, we tell that organisation without undue delay, and in any case within [24] hours of becoming aware of it, and help it decide what to do, including telling the Information Commissioner’s Office and the people affected where needed. After every significant incident we review what happened and what we will change.

11. Our people and suppliers

  • Everyone at LinkSync is bound by confidentiality, trained in security and data protection when they join and every year, and given only the access their role needs. [Background checks: confirm what is carried out.]
  • Access is removed on the day someone leaves.
  • We check the security of every supplier that handles personal information before we use it, and bind it by contract. See Sub-processors.

12. Assurance and certification

  • [Certification held, or planned with target date.]
  • We support organisations completing their own security questionnaires and sector assessments, such as the NHS Data Security and Protection Toolkit.
  • Customers can ask for a summary of our latest independent security test, under confidentiality, and for our completed security questionnaire.
  • Our Data Processing Agreement sets out our security commitments in contract.

13. What organisations can do

  • Give people only the access their job needs, and remove it promptly when they leave.
  • Block a lost or stolen phone the same day.
  • Keep the email accounts people use to sign in secure.
  • Keep GeoSync stock locked away and check the stock log.
  • Review your audit trail and act on tampering alerts.
  • Protect anything you export. [Planned: keep the keys you use to connect your own systems secret.]

14. Reporting a security problem

If you think you have found a security weakness in LinkSync, please tell us. We are grateful to people who report problems responsibly.

How to report

Email security@linksync.co.uk with:

  • what you found, and where;
  • the steps to reproduce it;
  • what you think the impact could be; and
  • how to contact you, if you would like us to.

[A key for sending encrypted reports, and a security.txt file, will be published at [location].] Please don’t report security problems through social media or public forums.

What we commit to

  • We will acknowledge your report within [3] working days.
  • We will tell you whether we have confirmed the problem, and our plan to fix it, within [10] working days.
  • We will keep you updated until it is fixed, and tell you when it is.
  • With your permission, we will thank you publicly once it is fixed.
  • [We don’t currently offer payment for reports.]

Safe harbour

If you act in good faith and follow these rules, we will not take legal action against you or report you to the police for your research, and we will consider it authorised. If someone else takes action against you for research that followed these rules, we will make it known that it was authorised. This does not cover anything outside these rules. [Solicitor to confirm wording, including with reference to the Computer Misuse Act 1990.]

The rules

  • Only test against accounts and information that are your own, or that you have permission to use.
  • If you come across anyone else’s personal information, stop, don’t keep or share it, and tell us straight away.
  • Don’t do anything that could disrupt or degrade LinkSync, such as denial-of-service attacks or heavy automated scanning.
  • Don’t tamper with GeoSyncs fitted at any place, or try to enter any property. If you want to test a GeoSync, ask us and we will supply one.
  • Don’t try to trick, pressure or impersonate our staff, customers or users.
  • Don’t try to record a false visit at a real organisation.
  • Give us reasonable time to fix the problem, normally up to [90] days, before telling anyone else about it.

Out of scope

  • Reports from automated scanners with no demonstrated impact.
  • Missing best-practice settings with no demonstrated impact.
  • Problems that need a phone that has already been fully compromised, without showing how LinkSync’s checks would fail to catch it.
  • Problems in other companies’ services. Please report those to them.