Trust
A record you can putin front of a reviewer.
This page is maintained by Bastrion to answer common questions about how the platform handles records, access, and accountability. It describes product behaviour, not an independent audit or certification.
Operational recordkeeping
What the platform records and keeps.
- Attribution on every step
- Submissions, reviews, approvals, returns, and releases are recorded against the account that performed them, with the time they occurred.
- Corrections stay visible
- When a report is returned and corrected, the earlier version and the supervisor reason remain part of the record rather than being replaced.
- Retention under your control
- Retention windows for reports, incidents, documents, and exported datasets are configured by your administrators inside the platform.
- Structured exports
- Records can be extracted as defined datasets over a chosen range, so a request for evidence does not become a manual reconstruction.
Audit and accountability
Activity history is append-only.
- Tenant audit history
- Administrators can review account activity such as configuration changes, review decisions, releases, and access changes within their own organisation.
- Platform oversight
- Bastrion platform administrators maintain a separate, cross-tenant record of high-risk platform actions, including support access.
- Support access is recorded
- Where Bastrion staff view an account to resolve a support issue, that access is logged and visible in the platform audit record.
Role-based access
People see the part of the record they are accountable for.
Officers
Their own shift work, submissions, corrections, and notices.
Supervisors
Review queues, quality findings, incidents, and site oversight.
Administrators
Configuration, compliance, deployment, billing, and audit history.
Clients
Approved reports, released incidents, summaries, and documents.
Client visibility controls
Nothing reaches a client by accident.
- Release is deliberate
- Client accounts see content once it has been approved and released. Drafts, in-review work, and returned reports are not exposed.
- Scoped to contracted sites
- A client account is mapped to specific sites. Activity outside those sites is not visible in the portal.
- Internal traffic stays internal
- Review notes, correction history, quality findings, and internal notifications are excluded from the client portal by design.
Reliability and shared responsibility
Where our responsibility ends and yours begins.
Bastrion provides the platform, the access controls, and the recordkeeping behaviour described on this page. Your organisation decides who is granted access, what your templates require, which sites a client can see, and how long records are retained.
Not a certification
Nothing on this page is a compliance certification, an audit opinion, or a legal guarantee. If your procurement process requires formal documentation, contact us and we will respond with what can be evidenced in writing.
Contact for documentationNext step
Bring your review requirements to the conversation.
Tell us what your clients, insurers, or regulators ask of your reporting, and we will show how the record is produced and retained.