Trust

A record you can putin front of a reviewer.

This page is maintained by Bastrion to answer common questions about how the platform handles records, access, and accountability. It describes product behaviour, not an independent audit or certification.

Operational recordkeeping

What the platform records and keeps.

Attribution on every step
Submissions, reviews, approvals, returns, and releases are recorded against the account that performed them, with the time they occurred.
Corrections stay visible
When a report is returned and corrected, the earlier version and the supervisor reason remain part of the record rather than being replaced.
Retention under your control
Retention windows for reports, incidents, documents, and exported datasets are configured by your administrators inside the platform.
Structured exports
Records can be extracted as defined datasets over a chosen range, so a request for evidence does not become a manual reconstruction.

Audit and accountability

Activity history is append-only.

Tenant audit history
Administrators can review account activity such as configuration changes, review decisions, releases, and access changes within their own organisation.
Platform oversight
Bastrion platform administrators maintain a separate, cross-tenant record of high-risk platform actions, including support access.
Support access is recorded
Where Bastrion staff view an account to resolve a support issue, that access is logged and visible in the platform audit record.

Role-based access

People see the part of the record they are accountable for.

Officers

Their own shift work, submissions, corrections, and notices.

Supervisors

Review queues, quality findings, incidents, and site oversight.

Administrators

Configuration, compliance, deployment, billing, and audit history.

Clients

Approved reports, released incidents, summaries, and documents.

Client visibility controls

Nothing reaches a client by accident.

Release is deliberate
Client accounts see content once it has been approved and released. Drafts, in-review work, and returned reports are not exposed.
Scoped to contracted sites
A client account is mapped to specific sites. Activity outside those sites is not visible in the portal.
Internal traffic stays internal
Review notes, correction history, quality findings, and internal notifications are excluded from the client portal by design.

Reliability and shared responsibility

Where our responsibility ends and yours begins.

Bastrion provides the platform, the access controls, and the recordkeeping behaviour described on this page. Your organisation decides who is granted access, what your templates require, which sites a client can see, and how long records are retained.

Not a certification

Nothing on this page is a compliance certification, an audit opinion, or a legal guarantee. If your procurement process requires formal documentation, contact us and we will respond with what can be evidenced in writing.

Contact for documentation

Next step

Bring your review requirements to the conversation.

Tell us what your clients, insurers, or regulators ask of your reporting, and we will show how the record is produced and retained.