How programme data is handled
This page separates what is in place today from what is still being completed, so you can judge for yourself.
In place
- A dedicated deployment per programme. Your data is not stored alongside other clients' data.
- Two-factor sign-in with authenticator-app codes (TOTP).
- Sessions held in HTTP-only cookies, which page scripts cannot read. Refresh tokens are rotated and stored only as hashes.
- Role-scoped access. An implementing-unit user sees their own unit. Donor users see aggregate views. When access is refused, the reason is given.
- An audit trail of who changed what and when, including the previous value.
- Soft deletion. Deleted records are retained and marked, not erased, so the history stays complete.
Being completed before general availability
- Encrypted, off-site daily backups with tested restores.
- Rate limiting on sign-in and AI features.
- Self-service password reset by email.
- External uptime monitoring and error tracking.
Pilot agreements state which of these are in place on the date of signing.
Where data is hosted
Hosting region is agreed with each client before deployment. Where national law or ministry policy requires data to stay in the country, an in-country or client-hosted deployment is available.
AI features
The AI assistants send the question and the relevant programme records to Anthropic's Claude models to produce an answer. They can be switched off for a deployment. Under Anthropic's commercial terms, data sent through its API is not used to train its models. Answers are checked against the data before they are shown, and are cited or withheld.
Report a vulnerability
Write to security@projectsmanager.ai. We acknowledge reports within three working days.