Skip to content
MapMyStaff
Help Centre · Security and data

Data, access, or validation: start with the right question.

These topics are related, but they do not mean the same thing. This collection separates documented data categories, protected access, and technical controls that apply to specific flows.

One page does not prove everything.Scope depends on the documented component, flow, configuration, and version.

Three different questions that should not be mixed

The trust dossier distinguishes observed data categories, authentication and access mechanisms, and technical validation that applies to specific endpoints. None of these elements should be generalized to the whole platform.

3 guides

Choose the right guide

Open the guide that matches exactly what you want to verify.

What data may MapMyStaff process?

See the documented categories: Web requests, accounts, configured operational data, and certain technical data.

Understand processed data

What is documented about roles and permissions?

Understand what is confirmed for protected flows and what still remains to be finalized in the complete access matrix.

Review documented access

Which rules may be rechecked server-side?

Understand why certain fields, request types, routes, addresses, or rules may be validated server-side depending on the module and endpoint.

Understand server-side validations
Guardrails

What this collection does not prove

The trust dossier confirms specific mechanisms, not absolute security or identical behaviour everywhere.

  • An independent certification or automatic compliance.
  • A complete role and permission matrix: it still has to be finalized.
  • That every action uses App Check, reCAPTCHA, or the same server-side validation.
  • The absolute absence of incidents, errors, loss, or unauthorized access.
Support and privacy

Document unexpected behaviour

If an access rule or validation produces an unexpected result, note the page, action, observed result, and exact message. Never send a password, authentication code, key, token, or secret.

Contact support

Did this page help you choose the right resource?