I AM THE FEATURE™ T.I.M.E. Business Blockbuster Workbook — $49.99 $14.84

Book Now
Security & Compliance

Cybersecurity Guidelines for Government

How Tapn.vip protects government, hospital, and enterprise tenants — and what your agency should do on its side. Applies to white-label deployments and standard organizations.

1. Identity & Access Management

  • ▸ Multi-factor authentication (TOTP authenticator apps) is REQUIRED for all privileged roles — admins, org managers, and support staff.
  • ▸ Role-based access control (RBAC) with least-privilege system roles; permissions are system-defined and cannot be self-escalated.
  • ▸ Organization scoping: users in one agency/department cannot access another organization's data.
  • ▸ Session tokens are short-lived JWTs; privileged sessions require a fresh MFA challenge.

2. Data Protection & Encryption

  • ▸ All traffic is encrypted in transit with TLS 1.2+ (TLS 1.3 preferred) and HSTS with a 2-year max-age, includeSubDomains, and preload.
  • ▸ Passwords are hashed with bcrypt; credentials are never stored or logged in plaintext.
  • ▸ Vault documents are stored in access-controlled object storage; share links are expiring and revocable.
  • ▸ Emergency Medical ID data is only exposed through explicit member opt-in.

3. Audit & Accountability

  • ▸ Immutable audit trail of privileged actions: logins, role changes, data exports, org changes, and MFA events.
  • ▸ Crash and error reports are collected centrally with deduplication for incident triage.
  • ▸ Visitor analytics collect approximate location only (city/state level) — never precise GPS without explicit consent.

4. Threat Monitoring & Incident Response

  • ▸ Continuous CVE monitoring against the NVD (National Vulnerability Database) for the platform's software stack.
  • ▸ Rate limiting on authentication and public endpoints to blunt brute-force and scraping attempts.
  • ▸ Escalation flags (URGENT/CRITICAL) for safety-relevant AI interactions, with a reviewable escalation log.
  • ▸ Incident workflow: detect → contain → notify affected organizations → remediate → post-incident review.

5. Personnel & Governance (for your agency)

  • ▸ Assign a system owner and a security point of contact for your organization's Tapn.vip tenant.
  • ▸ Review member roles quarterly; remove access within 24 hours of personnel separation.
  • ▸ Require agency-managed email addresses for all org accounts; prohibit shared logins.
  • ▸ Train staff on phishing resistance — Tapn.vip will never ask for passwords or MFA codes by email.

6. Data Handling & Residency

  • ▸ Members can export their complete data (GDPR/CCPA Right to Access) and request deletion.
  • ▸ Location sharing is consent-based and can be disabled per profile at any time.
  • ▸ Geofenced event features (auto check-in, door sales) are opt-in per event and clearly disclosed to attendees.
  • ▸ White-label tenants receive logically isolated organization data scopes.

7. Standards Alignment

  • ▸ Controls are aligned to NIST Cybersecurity Framework 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover.
  • ▸ Access-control and audit practices follow NIST SP 800-53 AC/AU control family intent.
  • ▸ MFA implementation follows NIST SP 800-63B Authenticator Assurance Level 2 (AAL2) guidance.
  • ▸ For CJIS, HIPAA, or FedRAMP-specific requirements, contact us for a tailored control mapping for your tenant.

Need a formal control mapping or a security questionnaire completed?

Contact us through your organization admin panel or the support chat — we respond to government and enterprise security reviews.

Add Tapn.vip to your home screen

One tap to your digital passport — no app store needed.