Zero-Trust by Default
MapFlow is built on a zero-trust security model. Several powerful features are deliberately disabled by default — not because they don't work, but because enabling them introduces data-sharing or residual-risk surfaces that require explicit InfoSec awareness and sign-off. This guide explains why each area is disabled and how to enable it safely when your engagement permits.
Design Principles
Features Disabled by Default
These features introduce data-sharing or residual-risk surfaces. They are off by default and require explicit admin enablement with InfoSec awareness.
Architecture Controls (Always Active)
These controls are not toggleable — they are baked into the architecture. Understanding them helps you answer InfoSec and DPIA questions from the Council.
Quick Reference: Default Posture
| Control | Default | Risk if enabled |
|---|---|---|
| AI Field Mapping | OFF | Citizen data shared with AI provider |
| Deep PII Scan | OFF | Row-level text sent to AI provider |
| ConvertAPI Compression | OFF (Local Proxy default) | Document bytes sent to EU sub-processor |
| AI Residency Enforcement | ON | Disabling removes UK model pinning |
| Deep PII Decrypted Access | No standing access | Decrypted citizen data visible to named user |
| GeoIP Non-UK (admin) | Warn | Weakening to off removes detection |
| GeoIP FireHOL | Block | Weakening allows known-attacker IPs |
| Postgres Superuser | Burned post-setup | N/A — cannot be re-enabled |
| PII Key Lifecycle | Per-phase destruction | N/A — architecture control |
| Council Master Key | Council-held | N/A — sovereign custody |
| Blind-Index Search | Active (HMAC-SHA256) | N/A — architecture control |
| Posture Monitoring | Weekly + on-demand | N/A — always active |