Limit access to a defined need
Administrative and provider access should be assigned to identifiable people, reviewed periodically, and removed when no longer required.
Trust & security
We treat security as an ongoing practice involving people, access, providers, software, and documented response—not as a single feature.
Administrative and provider access should be assigned to identifiable people, reviewed periodically, and removed when no longer required.
Material changes should be tested, reviewed, and introduced through a controlled release process appropriate to the system’s risk.
Security concerns relating to JRSO Tech Group can be reported to support@jrsotech.com. Do not include passwords, secret keys, or unnecessary personal data in the first message.
Third-party services should be selected for a documented purpose and accessed only within the permissions required for that purpose.