Skip to main content

Public summary

Security overview

A high-level summary of the system, sign-in protections, and access controls for an organization’s first review.

Updated
August 30, 2026
Scope
Public summary
Escalation
Formal follow-up available

Current control position

Blacklight separates public, partner, and administrative authority. Partner access is server-scoped to one organization and its assigned role or locations, while the highest-risk actions require a current session, recent authenticator verification, and an auditable reason.

Security overview · Current public evidence boundary

Current safeguards

What Blacklight currently does

These statements describe implemented controls and their limits in plain language. They are not a certification, legal opinion, or substitute for an institution-specific contract requirement.

01

Public requests, partner accounts, and admin tools are separated so the same person does not automatically have the same level of access everywhere.

02

Sensitive actions such as billing changes, privacy handling, partner-access changes, and high-risk admin actions sit behind stronger authentication requirements and auditability.

03

The public request form stays simple, while privileged controls are limited to signed-in staff and authorized partner users.

04

Production migrations and runtime releases use reviewed source, exact-target checks, durable release controls, health verification, and recorded rollback inventory rather than an untracked dashboard-only deployment path.

05

Blacklight also maintains an automated accessibility baseline across key public review surfaces and preview-safe portal shells, while keeping the trust claim itself narrower than a formal accessibility certification.