Cookie Policy & Session Management
Last Updated: September 2026
At BlueGrid Core Solutions, we prioritize absolute transparency in our technical operations. This Cookie Policy exhaustively details how, why, and when we utilize cookies, local storage, session variables, and similar cryptographic tracking technologies within our Enterprise Command Center and associated public-facing web properties. Given our role as an enterprise technology holding company with five specialized branches, our approach to session management is highly secure, strictly utilitarian, and unapologetically focused on performance and authentication rather than invasive tracking.
1. Technical Definition of Cookies
Cookies are small, encrypted text files dispatched from our Next.js backend servers to your web browser (e.g., Chrome, Edge, Firefox) when you interact with our Services. They are locally stored on your computer's hard drive or mobile device. These files serve as a memory mechanism, allowing our backend infrastructure to recognize your specific browser session, persist your authenticated state, and maintain continuous service delivery without requiring you to re-authenticate for every single HTTP request. We employ both "Session Cookies," which are automatically obliterated when you close your browser, and "Persistent Cookies," which remain until a predefined cryptographic expiration date or until you manually clear them.
2. The "Portal-Only" Strict Usage Principle
BlueGrid Core Solutions fundamentally rejects the pervasive industry practice of utilizing invasive, cross-site third-party tracking cookies for targeted advertising or data brokering. Our deployment of cookies is governed by a strict "Portal-Only" principle:
- Zero Ad Tracking: We do not deploy Facebook Pixels, Google Ads tracking, or any other marketing-centric cookies on the Enterprise Command Center.
- Zero Cross-Site Tracking: Our cookies cannot track your browsing behavior across other websites. They are tightly scoped to the bluegridcoresolutions.co.za domain and its subdomains.
- Zero Data Monetization: The data contained within our cookies is entirely operational. It is never sold, leased, or licensed to third-party data aggregators under any circumstances.
3. Exhaustive Breakdown of Cookies Used
Our systems deploy a minimal, highly secure set of cookies categorized strictly into "Essential / Strictly Necessary" functions. Without these cookies, the Enterprise Command Center would categorically fail to function.
A. The Access Token (accessToken)
This is the cornerstone of your active session. When you successfully authenticate—passing both your credentials and your TOTP Multi-Factor Authentication (MFA) challenge—our Next.js backend generates a cryptographically signed JSON Web Token (JWT).
- Purpose: Validates your identity and Role-Based Access Control (RBAC) permissions for every API request you make to the server.
- Security Posture: It is configured with the
HttpOnlyflag, meaning it is mathematically impossible for client-side JavaScript (and by extension, Cross-Site Scripting (XSS) attacks) to read it. It is also markedSecure(transmitted only over HTTPS) andSameSite=Laxto aggressively mitigate Cross-Site Request Forgery (CSRF) vulnerabilities. - Lifespan: This token is highly ephemeral, expiring completely after 1 hour (60 minutes).
B. The Refresh Token (refreshToken)
Because the Access Token expires rapidly for security purposes, the Refresh Token exists to maintain a seamless user experience.
- Purpose: When your Access Token inevitably expires, the frontend client silently sends this Refresh Token to our
/api/auth/refreshendpoint. If valid, the server seamlessly provisions a new Access Token in the background, preventing abrupt, frustrating logouts while you are working in the portal. - Security Posture: Like the Access Token, it is strictly
HttpOnly,Secure, andSameSite=Lax. It is also rotationally invalidated upon use in highly secure contexts. - Lifespan: Expires after 7 days of absolute inactivity.
C. Cookie Consent Preferences (bluegrid-cookie-consent)
When you interact with our Cookie Consent banner, we store your compliance preferences in a persistent cookie to ensure we do not repeatedly prompt you.
- Purpose: Remembers whether you have accepted strictly necessary cookies and your specific UI choices regarding the banner.
- Security Posture: Non-sensitive string boolean; readable by the client to adjust the banner rendering instantly.
- Lifespan: Expires after 365 days.
D. LocalStorage (Client-Side State)
While technically not "cookies," we utilize the browser's localStorage API for non-sensitive, UI-enhancing state persistence.
- Theme Preferences: We store a simple
themestring ("light" or "dark") to instantly render the portal in your preferred visual aesthetic before the React application fully hydrates. - Role Hints: We may store a non-sensitive
userRolehint to conditionally render navigation menu items instantly. Note: Actual security authorization is always enforced server-side via the HttpOnly JWT; modifying this local storage value cannot grant unauthorized access to restricted endpoints.
4. The Role of Multi-Factor Authentication (MFA)
It is critical to understand the intersection of our cookies and our MFA implementation. Possessing a valid, unexpired session cookie is the result of successful MFA, not a replacement for it. When you initiate a login, our system requires your password. If successful, you do not receive the accessToken or refreshToken cookies. Instead, you receive a temporary status: 202 response and a highly restricted, 5-minute temporary token. Only upon successful verification of your 6-digit TOTP code (or via SSO enforcement) does the backend finally issue the powerful HttpOnly cookies that grant access to the Command Center. If you manually delete your cookies, your session is annihilated, and you must pass the full MFA challenge again to regain access.
5. Managing and Eradicating Your Cookies
You maintain total, sovereign control over your browser's cookie storage. You can configure your browser (Chrome, Edge, Firefox, Safari) to refuse all cookies, alert you when a cookie is being set, or automatically delete them upon exiting the browser. However, because our cookies are classified as "Strictly Necessary," disabling them will result in an immediate, cascading failure of the Enterprise Command Center. You will be completely unable to log in, view dashboards, or manage your infrastructure. We provide a secure "Sign Out" button within the portal; clicking this button actively commands the server to invalidate your tokens and instruct your browser to immediately delete the accessToken and refreshToken cookies, ensuring a clean, secure exit.
6. Policy Iteration and Contact Information
As we engineer new features, such as advanced behavioral analytics for threat detection, we may introduce new, strictly operational cookies. Any such additions will be documented here with full technical specifications. If you are an enterprise security auditor, penetration tester, or simply a client with deep technical inquiries regarding our session management architecture, please direct your correspondence to our engineering leadership at security@bluegridcoresolutions.co.za.