Controls around every location workflow
LocateNG limits access, records important actions and keeps each organization’s operational data isolated.
Secure, revocable links
Each recipient link uses a strong random secret. Only its cryptographic hash is stored. Links expire automatically and can be revoked before completion.
Organization isolation and access control
Records are scoped to an organization at the database layer. Role-based permissions control who can manage members, locations, developer projects and integrations.
Auditability
Request creation, link opens, resolution outcomes, recipient decisions and administrative changes are recorded with actor, resource and timestamp context.
Data minimization
Public pages expose only the context a recipient needs to respond. API logs avoid request payloads and full secrets are never displayed after creation.
API and webhook security
API credentials and webhook secrets are generated server-side, stored as hashes and revealed only once. Webhook deliveries are signed and retry history remains visible to authorized team members.
Clear scope
A confirmation records that the intended recipient accepted a resolved location for a stated purpose. It does not establish identity, residence, ownership or legal status.