Sign in

Two doors into the same record.

Staff at a partner organisation work the spine. Data subjects and their appointed attorneys work their own record. Both surfaces run on the same API, the same consent gates and the same audit chain — the difference is what you are permitted to see.

What a partner can do

Everything a permission allows and nothing it does not. Roles run from viewer through analyst and compliance to admin, and every route checks a permission rather than a role name. Unsealing someone's personal information needs admin or compliance specifically — and writes its own audit entry when it happens.

What a data subject controls

The consent switches are real. Revoking credit_scoring from your own account means the next scoring call for you fails closed with a consent error — not a stale score served quietly. The revocation is appended to the chain and cannot be deleted to make later processing look authorised.

How an attorney acts

A mandate is granted by the principal, scoped to view-only, consent or full, and optionally given an expiry. Only the principal can revoke it, an attorney cannot pass it on, and every action taken under it is recorded against the mandate on the audit chain.

Trouble signing in? Accounts are locked after repeated failures, with the lock growing on each further attempt — wait out the period shown rather than retrying. For anything else, contact us.