Security
Authorization decided per data element, not per screen.
Hiding a screen is not security. Every request for data is authorised server-side against the specific record being requested.
Identity
- Identity is verified once, with an Investor Passport
- The Passport is reusable across Investor Services and InvestNow
- Verification state is visible to you at all times
- Step-up authentication is required for high-risk actions
Authorization
The employer portal and the account-holder portal are not the same application with different menus. They are different sets of authorised requests. An employer request for an individual balance is not hidden — it is refused, and the refusal is recorded.
This is the model B5 Secure enforces across the portfolio: every data element, purpose, delegation and decision is authorised individually, and each decision leaves evidence.
Sessions and step-up
| Action | What is required |
|---|---|
| View balances and activity | Authenticated session |
| Change contribution rate | Authenticated session |
| Change investments | Authenticated session |
| Change beneficiaries | Step-up authentication |
| Change bank details or payout instructions | Step-up authentication |
| Request a distribution | Step-up authentication |
| Add an employer administrator | Step-up authentication |
Evidence
Every authorisation decision, every state change and every document delivery produces a record that can be produced later. That is what allows an employer to demonstrate a contribution was remitted, and an account holder to demonstrate an instruction was given.
What we will not claim
No system is unbreakable, and we do not describe ours as “bank-grade” or “military-grade” because those phrases mean nothing. What we will tell you is exactly which controls exist, which are independently examined, and which are not yet in place.