Travel Document Handling & Secure Vault Policy
Download PDF1. Restricted classification
Passports, identity documents, visas and comparable travel records are classified as restricted information.
2. Collection
Collect only the document or information reasonably necessary for the identified travel purpose. Avoid collecting unrelated pages or information.
3. Storage
Restricted documents are stored through the authenticated client-vault workflow, encrypted before storage and kept outside the public website directory.
4. Authorisation
Access is trip-specific and role-based. A client should only see documents associated with an authorised trip; administrators require a legitimate business purpose.
5. Integrity and logging
Uploads and downloads are associated with integrity hashes and audit events where the production architecture supports them.
6. Prohibited practices
Do not store restricted travel documents in browser localStorage, public links, source-code repositories, ordinary analytics services or unsecured shared folders.
7. Deletion
Delete or cryptographically destroy restricted documents when their operational/legal purpose ends, subject to lawful retention needs.
Trust Centre