Connact Networks · Ownership and trust
Ownership, trust and architectureTrust is designed into the product relationship.
Ownership, identity, access, data flows and deployment are not generic feature claims. They are explicit decisions made with each institution, in discovery, and then delivered as stated.
If your IT or security team sent you here, this page covers four things: who controls the data and the deployment, what the technology stack is, how access is granted, and where to send a security question. Each has its own section below.
Your product. Your brand. Your data. Your rules.
Product direction
The outcomes, audiences, experience priorities and roadmap belong to the institution.
Brand
Every client platform is separately named and expressed. It is never presented as a Connact-branded tenant.
Data
Authoritative sources, exchange boundaries, hosting and responsibilities are agreed before delivery begins.
Governance
Eligibility, access, moderation, publishing and recognition rules are controlled by your organisation.
We do not hold your data hostage.
Full export, any time, at no cost. An agent can now move a member’s records in seconds, so data lock-in stopped being a real moat some time ago and we do not pretend otherwise. What holds a member to this network is the witnessed history it holds for them, and that has to be earned.
Connact-managed cloud
Managed infrastructure with agreed regions, environments and data boundaries. The most direct path from discovery to launch.
Your cloud, your controls
Deployed inside the institution’s own cloud or private environment, under its security, identity and operational controls.
In-country residency
Where sovereignty requires it, data and workloads stay in your jurisdiction. We validate this during discovery, not promise it afterward.
Arabic-ready by design
Right-to-left layout, typography and bilingual information architecture designed in from the start, never retrofitted.
A standard enterprise stack your team can run.
No exotic dependencies and no mandatory external services. These are mature, widely operated components that government and enterprise IT teams already know, deployed into your environment as containers.
.NET 8 on Linux containers
A vendor-supported runtime with long-term support, familiar to enterprise and government IT.
React with server-side rendering
Fast, accessible, SEO-ready delivery on a mainstream front-end stack.
Native iOS and Android
React Native from one shared codebase, published under the institution’s own developer accounts.
PostgreSQL
The most trusted open-source relational database. Your data lives in your instance and stays portable by design.
Self-hosted search engine
People, expertise and knowledge discovery without sending anything to third-party services.
S3-compatible object storage
Works with your cloud provider’s storage or a fully self-hosted object store.
Redis
Standard in-memory infrastructure for performance, sessions and background work.
OAuth 2.0 / OpenID Connect
Integrates with your SSO and identity providers. Consent and access are explicit, per grant.
OpenAPI, webhooks and SDK
Contract-documented REST APIs, event webhooks and a TypeScript SDK for your own teams.
Assurance aligned with the agreed deployment.
Architecture and threat review, access and data-flow mapping, residency and exit planning, accessibility validation, and deployment hardening are delivery criteria for each engagement, validated against your environment.
One boundary, and one thing deliberately outside it.
A reference deployment. The engine and its data run inside your perimeter, under your keys. The only component that sits outside is the notary witness, because a witness the institution controls cannot witness anything.
Your website
- Publishing, SEO and discovery
- Anonymous visitors
- Hands identified people onward
Connact engine
Deployed as containers into your environment.
Your systems
- CRM or membership system
- Identity provider and SSO
- CMS and media
External notary witness
A public mirror receives each published root hash. Neither Connact nor your own team can rewrite it. That is the only reason a dated record proves anything.
What we can state today, stated plainly.
This is a young platform being honest about where it stands, not a compliance page written to sound more finished than it is.
Encryption in transit
Every member-facing and administrative connection runs over HTTPS. Nothing is served in plain text.
Access is explicit and scoped
Sign-in runs through OAuth 2.0 and OpenID Connect against your identity provider. Even automated access, such as an agent acting on a member’s behalf, is scoped to named records, time-limited and revocable at any time. See how that works on the platform page.
Your deployment boundary
The application, database, search, storage and cache run inside an environment you control: your cloud or ours, under your keys, as shown in the diagram above. We do not hold a copy of your data outside that boundary.
A direct line for security questions
Write to hello@connact.me with “security” in the subject. It reaches the people doing the engineering, not a support queue, and a security review is a normal part of discovery for every engagement.
What we do not yet have: a formal certification such as ISO 27001 or SOC 2, a published bug bounty, or a standing uptime commitment for the shared cloud option. We would rather tell you that directly than stay quiet about it or claim something we cannot back up. Where a specific certification, SLA or residency guarantee matters to your evaluation, it is the kind of thing we scope and commit to during discovery, in writing, against your actual requirement.
Bring your security and IT team to the first conversation.
Most of what a review needs is settled in discovery: the deployment model, the data boundary, the identity integration and the residency requirement. Having the people who will ask those questions in the room early saves a round trip.