MELscope

Security & Data Protection Pack

Version 1.0 · 28 July 2026 · MELscope, operated by ImpactSpring Smart Farm, a business registered in Papua New Guinea.
Written for procurement teams, donor due-diligence reviewers and M&E leads assessing MELscope. Reviewed at least annually and on any material change.

This document describes how MELscope is built, hosted and operated, and what happens to your project and beneficiary data inside it. It is deliberately specific, and it is deliberately honest about what MELscope does not yet have. If a control matters to your organisation and is not listed here, assume we do not have it and ask us.

1. At a glance

ServiceMELscope — monitoring, evaluation and learning platform for donor-funded projects
OperatorImpactSpring Smart Farm, Port Moresby, Papua New Guinea
Delivery modelMulti-tenant SaaS, browser-based, no installed software
Data locationAWS Asia Pacific (Sydney) — ap-southeast-2, Australia
DatabasePostgreSQL 17 on Supabase, row-level security enforced on every table
EncryptionTLS 1.2+ in transit; AES-256 at rest (AWS-managed)
AuthenticationEmail and password via Supabase Auth; minimum 8 characters on sign-up
Certifications held by MELscopeNone. See section 2.

2. What MELscope does not have

We would rather you learn this here than in month three of a contract.

  • No SOC 2, ISO 27001 or equivalent certification. MELscope has not been independently audited against a security framework. Our infrastructure providers hold these certifications; MELscope as an organisation does not.
  • No independent penetration test has been carried out on the application to date.
  • MELscope is operated by a very small team. There is no 24/7 staffed security operations centre and no follow-the-sun support rotation. Support is by email during Papua New Guinea business hours.
  • No formal uptime SLA is offered on the standard plans. We do not currently publish a status page.
  • No single sign-on (SSO/SAML) and no multi-factor authentication at present. Access is email and password.
  • No offline data collection. MELscope requires connectivity; it is an indicator, evidence and evaluability layer, not a field data-collection tool.

If your procurement process has a hard requirement for any of the above, MELscope will not pass it today, and we will tell you so rather than let you discover it late. Several of these are on our roadmap; none should be assumed to exist because it is common in larger products.

3. Hosting and infrastructure

MELscope runs on managed infrastructure rather than self-managed servers, which means the underlying patching, physical security and hardware lifecycle are handled by providers who are independently audited for it.

4. Access control and tenant isolation

This is the control that matters most in a multi-tenant system, so it is described precisely.

5. Beneficiary privacy

Client projects routinely record data about the individuals they serve. MELscope treats that as the most sensitive data on the platform.

Division of responsibility. Your organisation decides what beneficiary data to collect, on what lawful basis, and with what consent. MELscope is the processor: we store and protect that data and act on your instructions. We cannot and do not obtain consent from beneficiaries on your behalf.

6. Artificial intelligence and your data

MELscope can draft donor reports from your live project data using a large language model. Because this is the feature clients ask about most in review, it is set out in full.

7. Sub-processors

These are the third parties involved in delivering MELscope. We will give you at least 30 days' notice before adding a new sub-processor that handles personal data.

Sub-processorPurposeLocationPersonal data
Supabase Inc.Database, authentication, file storage, server-side functionsAWS Sydney, AustraliaYes — all project and beneficiary data
Amazon Web ServicesUnderlying cloud infrastructureSydney, AustraliaYes — as above, at rest
Anthropic PBCAI drafting of donor reportsUnited StatesAggregates and pseudonymised counts only; no beneficiary names
ResendTransactional email — invitations, approvals, trial noticesUnited StatesAccount holder names and email addresses only
CloudflareStatic site hosting and deliveryGlobal edge networkNo stored data; processes IP addresses in transit
CARTOBase map tiles for the project site mapGlobalNo; receives map tile requests and IP addresses
cdnjs / jsDelivrDelivery of open-source JavaScript libraries to the browserGlobalNo; receives IP addresses

8. Backup, continuity and data durability

MELscope's production database runs on a paid provider tier with automated daily backups retained for seven days. Projects are not suspended for inactivity, and the database is not dependent on a free service tier.

What this does and does not mean for your programme:

9. Vulnerability management and known issues

We run the platform's automated security linter against the database and review the findings. Open items as at the version date of this document, disclosed in full:

FindingSeverityAssessment
Leaked-password protection disabledWarningSign-up does not yet check passwords against known-breached password lists. Being enabled.
Public forms accept unauthenticated submissionsWarningIntentional — the access-request and contact forms must be usable by people without accounts. Submissions are write-only and readable only by platform administrators.
Permission-check functions callable before sign-inWarningLargely by design: these functions evaluate the caller's own identity and return only a boolean or a count. One usage-count function is being restricted to signed-in callers.
Networking extension installed in the default schemaWarningProvider-managed extension used for scheduled email notifications. Being relocated to a dedicated schema.

No findings at error severity were open at the version date. We will disclose material findings to affected clients rather than wait to be asked.

10. Incident response

11. Data retention, export and deletion

12. Personnel

13. Legal framework

MELscope is operated from Papua New Guinea, where the right to privacy is protected under Section 49 of the Constitution of the Independent State of Papua New Guinea. Because our clients implement projects funded by international donors — including the GEF, the European Union, DFAT and MFAT — we align our practices with internationally recognised data-protection principles, including those of the EU General Data Protection Regulation: lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. Our Data Processing Agreement is available for signature, and our Privacy Policy sets out how we handle personal data.

14. Document control and contact

This pack is reviewed at least annually and whenever there is a material change to hosting, sub-processors or security posture. If you are completing a vendor security questionnaire and need something not covered here, send it to us and we will answer it directly rather than leave a gap.

ImpactSpring Smart Farm
Port Moresby, Papua New Guinea
info@melscope.com