Authentication
The system has been built in-line with defence-in-depth zero-trust access principles.
To interact with the system in any way you need an authenticated and authorised request, and we take steps to limit the attack surface wherever practicable.
To ensure the validity of a request, we log and check all authentication requests from:
- end-users
- system-to-system interactions
- administrative user actions
For end-users signing into the system, the system uses Scottish Government’s strategic identity platform for secure Single Sign On (SSO) with Multi-Factor Authentication (MFA). MFA uses secure second factors, and supports Scottish Government’s device-managed authenticator apps.
Our service team will work with you during your onboarding to set up roles and permissions so your users can only access what they need to on our platform.