Skip to content
Connact NetworksConnact Digital SolutionsRequest a private consultation

Connact Networks · Ownership and trust

Ownership, trust and architecture

Trust is designed into the product relationship.

Ownership, identity, access, data flows and deployment are not generic feature claims. They are explicit decisions made with each institution, in discovery, and then delivered as stated.

If your IT or security team sent you here, this page covers four things: who controls the data and the deployment, what the technology stack is, how access is granted, and where to send a security question. Each has its own section below.

The governing principle

Your product. Your brand. Your data. Your rules.

Direction

Product direction

The outcomes, audiences, experience priorities and roadmap belong to the institution.

Identity

Brand

Every client platform is separately named and expressed. It is never presented as a Connact-branded tenant.

Custody

Data

Authoritative sources, exchange boundaries, hosting and responsibilities are agreed before delivery begins.

Control

Governance

Eligibility, access, moderation, publishing and recognition rules are controlled by your organisation.

We do not hold your data hostage.

Full export, any time, at no cost. An agent can now move a member’s records in seconds, so data lock-in stopped being a real moat some time ago and we do not pretend otherwise. What holds a member to this network is the witnessed history it holds for them, and that has to be earned.

Connact-managed cloud

Managed infrastructure with agreed regions, environments and data boundaries. The most direct path from discovery to launch.

Your cloud, your controls

Deployed inside the institution’s own cloud or private environment, under its security, identity and operational controls.

In-country residency

Where sovereignty requires it, data and workloads stay in your jurisdiction. We validate this during discovery, not promise it afterward.

Arabic-ready by design

Right-to-left layout, typography and bilingual information architecture designed in from the start, never retrofitted.

Technology, stated plainly

A standard enterprise stack your team can run.

No exotic dependencies and no mandatory external services. These are mature, widely operated components that government and enterprise IT teams already know, deployed into your environment as containers.

Application platform

.NET 8 on Linux containers

A vendor-supported runtime with long-term support, familiar to enterprise and government IT.

Web experience

React with server-side rendering

Fast, accessible, SEO-ready delivery on a mainstream front-end stack.

Mobile

Native iOS and Android

React Native from one shared codebase, published under the institution’s own developer accounts.

Data

PostgreSQL

The most trusted open-source relational database. Your data lives in your instance and stays portable by design.

Search

Self-hosted search engine

People, expertise and knowledge discovery without sending anything to third-party services.

Files and media

S3-compatible object storage

Works with your cloud provider’s storage or a fully self-hosted object store.

Caching and messaging

Redis

Standard in-memory infrastructure for performance, sessions and background work.

Identity

OAuth 2.0 / OpenID Connect

Integrates with your SSO and identity providers. Consent and access are explicit, per grant.

Integration surface

OpenAPI, webhooks and SDK

Contract-documented REST APIs, event webhooks and a TypeScript SDK for your own teams.

Assurance aligned with the agreed deployment.

Architecture and threat review, access and data-flow mapping, residency and exit planning, accessibility validation, and deployment hardening are delivery criteria for each engagement, validated against your environment.

Where it runs

One boundary, and one thing deliberately outside it.

A reference deployment. The engine and its data run inside your perimeter, under your keys. The only component that sits outside is the notary witness, because a witness the institution controls cannot witness anything.

Public

Your website

  • Publishing, SEO and discovery
  • Anonymous visitors
  • Hands identified people onward
Your cloud · your keys · your perimeterThe network

Connact engine

API.NET 8PostgreSQLrecords + notary logSearchself-hostedObject storageS3-compatibleRediscache + queues

Deployed as containers into your environment.

Authoritative

Your systems

  • CRM or membership system
  • Identity provider and SSO
  • CMS and media
Outside your perimeter, on purpose

External notary witness

A public mirror receives each published root hash. Neither Connact nor your own team can rewrite it. That is the only reason a dated record proves anything.

Reference deployment · the exact topology is agreed during discovery
For your security review

What we can state today, stated plainly.

This is a young platform being honest about where it stands, not a compliance page written to sound more finished than it is.

Encryption in transit

Every member-facing and administrative connection runs over HTTPS. Nothing is served in plain text.

Access is explicit and scoped

Sign-in runs through OAuth 2.0 and OpenID Connect against your identity provider. Even automated access, such as an agent acting on a member’s behalf, is scoped to named records, time-limited and revocable at any time. See how that works on the platform page.

Your deployment boundary

The application, database, search, storage and cache run inside an environment you control: your cloud or ours, under your keys, as shown in the diagram above. We do not hold a copy of your data outside that boundary.

A direct line for security questions

Write to hello@connact.me with “security” in the subject. It reaches the people doing the engineering, not a support queue, and a security review is a normal part of discovery for every engagement.

What we do not yet have: a formal certification such as ISO 27001 or SOC 2, a published bug bounty, or a standing uptime commitment for the shared cloud option. We would rather tell you that directly than stay quiet about it or claim something we cannot back up. Where a specific certification, SLA or residency guarantee matters to your evaluation, it is the kind of thing we scope and commit to during discovery, in writing, against your actual requirement.

The next step

Bring your security and IT team to the first conversation.

Most of what a review needs is settled in discovery: the deployment model, the data boundary, the identity integration and the residency requirement. Having the people who will ask those questions in the room early saves a round trip.