Security overview

Access Compass · accesscompass.uk · last reviewed July 2026

The most secure user data is the data you never hold. Access Compass is built local-first with no accounts and no central user database, which removes whole categories of risk before they can arise. This page explains our approach plainly, for anyone running security due diligence.

Design principles

Hosting and infrastructure

The website is served from Google Firebase Hosting on Google Cloud infrastructure, over an encrypted connection with a global content-delivery network. It holds no user accounts or user-created content.

Application security

Data handling

Because your data stays on your device, you hold the controls: you can view, edit and delete everything yourself, and clearing the site's storage removes it entirely. There is no copy on our side to recover or to lose. Full detail is in our data protection statement.

Scope, honestly. Access Compass is an information and signposting directory, not a medical device and not a clinical system. We describe what we do rather than claim certifications we do not hold. Where an organisation needs formal assurance, we are glad to complete security questionnaires and share what we can.

Reporting a security concern

If you believe you have found a security issue in Access Compass, please tell us at admin@adaidigital.co.uk so we can look into it promptly. We welcome responsible disclosure and will work with you in good faith.

All policies · Data protection · Privacy · Back to Access Compass