Skip to content

Technical overview

How Active Steward™ is delivered, secured and integrated, for IT, security and procurement teams evaluating the platform.

About Active Steward™

Active Steward™ is a cloud-hosted web application for product stewardship and regulatory compliance. It brings substance, product, registration, tonnage, document and study data into one system, and supports collaboration between in-house teams, regulatory experts, consortium members and clients.

It is delivered as a fully managed service. Penman Consulting builds, operates and supports it: hosting, patching, monitoring and backups are handled for you, and there is no on-premises infrastructure to install or maintain.

Pages in this section

  • Architecture Members

    How Active Steward™ is built and deployed: the technology stack, data flow, scalability and the instance and partition model that keeps each client's data apart.

  • Security Members

    The security controls in Active Steward™: single sign-on and two-factor authentication, role-based access by partition, file scanning, audit history, secure development and incident response.

  • Set up single sign-on to Active Steward™ with Microsoft Entra ID or Google using OpenID Connect: how it works, what to provide and automatic provisioning.

  • Compliance Members

    How Active Steward™ handles data protection and information security: GDPR and data processing agreements, data residency, governance, and the assurance documents available to clients under NDA.

  • Data Management Members

    How Active Steward™ organises and looks after your data: the data model, the data lifecycle from import to deletion, retention, residency, backups and how you can export your data.

  • Integrations Members

    How Active Steward™ connects with other systems: the REST API with permission-scoped keys, bulk import and export, and built-in integrations including IUCLID 6, ECHA Cloud Services, Microsoft Teams and leading…

  • How Active Steward™ stays responsive and available: background processing for large tasks, monitoring, planned maintenance, a 99.5% availability target, continuous backups and disaster recovery.

  • What your IT team needs for Active Steward™: supported browsers and devices, network and firewall settings, single sign-on, email and integrations.

  • How Active Steward™ is deployed and updated: the managed delivery model, separate production, staging and development environments, release and change management, versioning and maintenance windows.

  • Support Members

    How Active Steward™ is supported: email, phone and Help Centre channels, incident severity levels, onboarding and training, escalation and account management.

At a glance

Hosting and certification
Hosted on Akamai Cloud (formerly Linode) and Microsoft Azure, with primary hosting in London, UK. Operated under an ISO 27001-certified information security management system.
Web application
Active Steward™ runs in the browser, with nothing to install. Deployments are organised into instances, each with its own server and web address.
Partitioned data
Within an instance, partitions keep data for different clients or projects apart. Every record belongs to one partition, and users see only the partitions they are given access to.
Sign-in
Single sign-on with Microsoft Entra ID or Google, or a password with optional time-based two-factor authentication. Password expiry and account lockout apply.
Provisioning
User accounts can be created and deactivated automatically from Microsoft Entra ID using SCIM 2.0, with a fixed default role or one taken from Entra groups at first sign-in.
Access control
Roles are built from fine-grained permissions covering modules, record tabs and actions such as archive and delete, and can differ by partition.
Record protection
Uploaded files are virus-scanned and executable files are blocked. Key records can be archived instead of deleted, and change history is kept on key records.
REST API
A documented REST API with an OpenAPI reference. Keys are created by administrators and given only the permissions each integration needs.
Integrations
IUCLID 6, ECHA Cloud Services for poison centre notifications, Microsoft Teams and Outlook, and leading accounting packages.

Quality and support

The build includes automated tests, code-quality analysis and dependency vulnerability checks. Releases are made several times a year, with release notes in the Help Centre. Support is available by email, and by phone during UK office hours, and training is delivered at our offices, at yours or remotely.

How the platform develops

Development priorities are set with the people who use Active Steward™. The principles behind them are:

  • Driven by users and regulation: new capabilities are prioritised by client needs and regulatory change.
  • Security and compliance first: continued investment in security controls and audit readiness.
  • Scalable and dependable: ongoing work on performance and availability.
  • Interoperable: integration with enterprise systems, reporting tools and regulatory services.

Delivered changes are published in the release notes. The pages below give the detail. Most are available to registered users; single sign-on and client IT requirements are open to everyone.