Cloud Act version — InfoSec Compliance Guide

After
Original retained

This is the Cloud Act-affected version. The US Clarifying Lawful Overseas Use of Data (CLOUD) Act compels US-parent cloud providers to disclose customer data on lawful request — including data stored outside the US. The controls documented across this page exist to keep the AES key, plaintext PII, and AI processing outside the custody of any US-parent-owned provider. The original InfoSec Compliance Guide is preserved unchanged so the impact of the CLOUD Act can be compared side-by-side. Full rationale: CLOUD Act Posture Guide.

InfoSec Compliance Guide

Why features are disabled & how to enable them safely

Document ID: MF-ICG-01Version: 1.2Last Reviewed: August 2026Status: Published (Factual Baseline)

Zero-Trust by Default

MapFlow is built on a zero-trust security model. Several powerful features are deliberately disabled by default — not because they don't work, but because enabling them introduces data-sharing or residual-risk surfaces that require explicit InfoSec awareness and sign-off. This guide explains why each area is disabled and how to enable it safely when your engagement permits.

Design Principles

Zero data shared with AI providers by default
UK-only data residency end-to-end
No standing access to decrypted citizen data
Admin-gated features with mandatory InfoSec warnings
Council sovereign custody of recovery keys
Automated posture monitoring with admin email alerts

Features Disabled by Default

These features introduce data-sharing or residual-risk surfaces. They are off by default and require explicit admin enablement with InfoSec awareness.

Architecture Controls (Always Active)

These controls are not toggleable — they are baked into the architecture. Understanding them helps you answer InfoSec and DPIA questions from the Council.

Quick Reference: Default Posture

ControlDefaultRisk if enabled
AI Field MappingOFFCitizen data shared with AI provider
Deep PII ScanOFFRow-level text sent to AI provider
ConvertAPI CompressionOFF (Local Proxy default)Document bytes sent to EU sub-processor
AI Residency EnforcementONDisabling removes UK model pinning
Deep PII Decrypted AccessNo standing accessDecrypted citizen data visible to named user
GeoIP Non-UK (admin)WarnWeakening to off removes detection
GeoIP FireHOLBlockWeakening allows known-attacker IPs
Postgres SuperuserBurned post-setupN/A — cannot be re-enabled
PII Key LifecyclePer-phase destructionN/A — architecture control
Council Master KeyCouncil-heldN/A — sovereign custody
Blind-Index SearchActive (HMAC-SHA256)N/A — architecture control
Posture MonitoringWeekly + on-demandN/A — always active

Related Resources

The compliance models, regulatory briefs, and legislative interpretations provided on this site are for informational purposes only and do not constitute formal legal counsel. Data controllers retain sole responsibility for completing their independent statutory risk assessments under UK GDPR Article 35.