Can we use this for a controlled pilot review now?
Yes, for design-partner evaluation or a controlled pilot using agreed data boundaries; not for broad production rollout or live statutory-clock reliance.
Procurement-facing trust posture for early UK-based social landlords. Awaab's Law legal-scope wording is limited to the England social rented sector.
This is not legal advice, not a signed Data Processing Agreement, and not a completed security certification pack.
Yes, for design-partner evaluation or a controlled pilot using agreed data boundaries; not for broad production rollout or live statutory-clock reliance.
Current code supports role-bound operator keys, organisation allowlisting, single-use proof links, manual retention preview and deletion runs, JSON audit export, redaction stale-source checks, and prototype restore-probe evidence.
production SSO, MFA, SCIM, password policy, and persistent user directory; monitored security contact and approved incident rota; encrypted production storage and backups; customer-approved DPA/DPIA; certification evidence; and a signed or immutable evidence bundle.
Security incident-response draft exists at docs/security-incident-response-draft.md. It is not a live breach-notification SLA, and no security contact, tabletop evidence, or production incident rota has been approved.
Security contact and incident-intake draft exists at docs/security-contact-intake-draft.md. It is a placeholder only, not a live monitored security contact, and not a vulnerability disclosure programme.
Backup and restore draft exists at docs/backup-restore-dr-draft.md. It is not restore-test evidence. No approved production backup system, customer RPO, or customer RTO exists yet.