Production application object storage uses AES-256 encryption to protect stored information. Configured integration secrets are encrypted separately, helping protect the credentials used to connect your services to other systems.
Encryption works alongside permissions and the service’s data-handling choices. Your team still decides which people and integrations can retrieve information, where exported copies are held and how long those copies are retained.
Use library permissions to restrict access to live submissions and files.
Review protection and retention in connected file stores and downstream systems.
Include storage, databases and backups in any service-specific assurance discussion.
HTTPS protects connections as people use Govform services. The main platform endpoint supports TLS 1.2 or later, and secure connections are used between its delivery service and application hosting.
Your service’s integrations extend the data journey beyond the platform. Choose secure endpoints for API calls and connected systems, and configure client certificates when the receiving system requires them.
Use approved secure endpoints for Production integrations.
Keep credentials in secret settings rather than in user-visible content.
Test certificate, authentication and connection failures before going live.
Library properties and secrets let you reuse configuration values across services while keeping sensitive credentials in encrypted secret settings. Separate values for QA and Production help avoid sending test activity to a live system.
Secret masking supports safer diagnostics, while authorised actions can use the credentials they need to call connected systems. Assign an owner for each credential and plan updates with the team that controls the receiving system.
Use secret settings for API credentials and other sensitive connection values.
Keep ordinary configuration in properties and sensitive values in secrets.
Test replacement credentials in QA and coordinate Production changes.
Set submission retention to match your service’s operational need and use supported deletion workflows to manage information through its lifecycle. Retention processing handles expired service records and relevant internal-file references according to the applicable data lifecycle.
Plan deletion across all the places the service uses. Response Hub history, archives, backups, exports and external file stores can have different handling arrangements. Removing information from one view does not describe every copy held elsewhere.
Set a retention period before your service starts collecting live information.
Assign responsibility for external file stores and downstream records.
Restrict deletion and export permissions to the roles that need them.
Library and service settings work together to control how your service handles information. Library roles and MFA govern team access; service authentication governs respondents; secrets, destinations and retention govern the data journey.
Use QA to test the configuration as a complete service. Check the experience for different roles, where uploaded files go, what integrations send, and who can view or export operational information.
Assign design, deployment and live-data responsibilities deliberately.
Verify authentication and sharing with the intended user roles.
Check destinations, notifications and retention before Production deployment.
File components provide configurable size and type restrictions, with virus scanning and document-processing options where supported. You can shape the evidence your service accepts and apply protection appropriate to its storage destination and workflow.
Supported document-processing features can reconstruct Office files, rasterise PDFs, inspect document links or remove image metadata. Choose settings to fit the evidence you need, and test how processed files appear to users and reviewers.
Review scanning settings for both Govform storage and external destinations.
Set accepted types and file sizes to suit the receiving systems.
Test rejected, failed and processed uploads as well as successful files.