System security

Security designed into the whole system

A business system should protect information by design: encrypted connections, controlled access, secure data rules and continuous review — not security added as an afterthought.

Every system we deliver uses a professionally managed security foundation. We then configure access and safeguards around your people, processes, information and level of risk.

Your information stays confidential. We are happy to sign an NDA before any detailed discussion.

Business leaders reviewing user access controls in a secure operations system

The security foundation

Protection at every layer of your Business Operations System

Security is not one feature. It is a connected set of controls covering the journey from a user's sign-in, through the application, to the database and every external service.

Encrypted connections

Published systems and custom domains use managed HTTPS certificates and TLS 1.2 or newer, protecting data in transit without relying on users to configure it.

Protected data storage

Business data is held in a managed database with encryption at rest, controlled access and daily database backups retained for approximately 14 days.

Managed identity

Sign-in, account sessions and password recovery use a dedicated authentication service, with social sign-in available where appropriate.

Server-side secrets

Private API keys and service credentials are kept in encrypted secret storage and used on the server, rather than being embedded in pages sent to a user's browser.

Security scanning

Automated checks review software dependencies, database policies, exposed functions, access controls and common code-level risks throughout delivery.

Operational monitoring

Published systems can be monitored for important visitor errors and code issues, helping us identify and investigate problems rather than waiting for users to report them.

Independent assurance

Evidence that supports customer confidence

Monitoring and secure engineering matter operationally. Independent verification gives procurement teams and larger customers additional confidence that recognised controls have been tested rather than simply described.

Organisation verified

Cyber Essentials Plus

Essential Systems is independently Cyber Essentials Plus certified. This verifies that our business devices, accounts and working practices meet recognised UK cyber security requirements within the scope of the certification.

Platform independently tested

Core-platform penetration test

Our reusable Business Operations System foundation has undergone independent penetration testing. Additional testing can be commissioned when a particular system handles especially sensitive information or has specific contractual needs.

Defence in depth

Five layers, from foundation to ongoing care

No single control carries the whole burden. Strong security comes from overlapping safeguards, careful configuration and responsible day-to-day operation.

  1. 01Secure foundationManaged hosting, encrypted connections, database protection and secure credential storage form the baseline beneath the application.
  2. 02Access designed around your businessWe define who should see, create, change and delete information. Those permissions are enforced against the data, not only represented in the interface.
  3. 03Safer application designSensitive operations are performed on the server, inputs are validated and privileged actions are kept separate from ordinary user activity.
  4. 04Review before releaseSecurity scans and manual review are used to identify inappropriate access, exposed credentials, vulnerable dependencies and unsafe endpoints before release.
  5. 05Monitor and improveSecurity is revisited as features, integrations and working practices change. Important findings are investigated and corrected as part of ongoing support.

Clear responsibilities

What is included, what we configure and what remains operational

We avoid vague promises. The technical foundation provides strong safeguards, we shape them for your system, and your business retains an important role in using it securely.

Included foundation

  • Managed HTTPS certificates and modern TLS
  • Managed database and authentication services
  • Encrypted secret storage for private credentials
  • Daily database backups with rolling retention
  • Dependency, database-policy and code security scanning
  • Monitoring for important application and visitor errors

Configured for your system

  • User roles and record-level access rules
  • Sign-in methods and account policies
  • Permissions for documents and uploaded files
  • Secure connections to third-party services
  • Retention, deletion and audit requirements
  • Appropriate separation of users and administrators

Shared operational responsibility

  • Keeping user accounts and devices protected
  • Removing access when people change roles or leave
  • Reviewing who should have privileged access
  • Using and sharing exported data responsibly
  • Agreeing legal and regulatory requirements
  • Commissioning specialist assurance where required

Honest assurance

Strong safeguards, without false certainty

A secure platform is an essential starting point, but it does not remove the need for careful design. The sensitivity of your data, integrations, user roles and operational processes all affect the final risk profile.

Automated scanning can identify important weaknesses, but it cannot guarantee that any application is completely secure. Our Cyber Essentials Plus certification applies to Essential Systems, and our independent penetration test applies to the reusable core platform; neither should be read as a guarantee or as certification of every customer system.

If your organisation has contractual, insurance, data-residency or sector-specific requirements, we establish those during discovery and agree any additional independent assurance before the relevant information is brought into the system.

Production target standard

A practical security baseline for ongoing operation

We are standardising the following controls across production systems. The precise combination remains subject to each application, its domain setup and the sensitivity of the information it processes.

  • Error monitoring on every production application
  • Uptime monitoring, customer-facing status information and alerts
  • Enhanced domain protection where technically appropriate
  • Automated external vulnerability scanning
  • Protected production branches with dependency and secret scanning
  • Automated database backups with quarterly restore tests
  • Multifactor authentication across administrative services
  • Annual independent penetration testing of the reusable core platform
  • A standard customer security pack and incident-response policy

Customer security pack

Clear information for review and procurement

Customers can request a concise security and data-protection pack containing the information relevant to their system. Sensitive technical detail is shared through an appropriate review process rather than published openly.

Hosting and infrastructure summary
Relevant hosting and database-provider security credentials
Data locations and subprocessors
Access-control arrangements
Encryption statement
Backup and recovery arrangements
Monitoring and vulnerability-management process
Incident-response and breach-notification process
Data-retention and deletion policy
Penetration-test executive summary
Cyber Essentials Plus certificate
Professional indemnity and cyber-insurance details

Security questions

What customers ask before trusting a bespoke system

01

Is our business data encrypted?

Connections to a published system are protected using HTTPS and modern TLS encryption. This protects information while it travels between a user's device and the system.

The managed database service also provides encryption for stored database data. Where a system connects to another service, we use secure server-side connections and keep private credentials out of the browser.

02

Can we control who sees different information?

Yes. Access can be designed around roles and responsibilities, so a person sees only the records and actions needed for their work. Rules can be applied at the data level, not just by hiding a screen or menu item.

For example, an engineer might see assigned visits while a manager sees the wider operation. Administrative permissions are kept separate from ordinary user access.

03

How are passwords and sign-in protected?

Systems can use managed email sign-in and, where appropriate, social sign-in. Password handling is provided by the managed authentication service rather than being improvised inside the application.

Additional options can include password-reset controls and checking for known compromised passwords. The exact sign-in policy is agreed for each system; specialist corporate identity requirements are scoped separately.

04

Are security checks carried out?

Yes. The professional delivery environment includes automated checks for vulnerable software dependencies, database access rules and common application security issues. Deeper code and access-control reviews are also available during development and before important releases.

Essential Systems is Cyber Essentials Plus certified, and our reusable core platform has undergone independent penetration testing. Automated scanning remains a valuable safety net, but no scanner or test can guarantee that a system is completely secure.

05

What happens if data needs to be restored?

The managed database is backed up daily, with a rolling retention period of approximately 14 days. This supports database recovery when required.

Uploaded files are stored separately from database backups, so file retention and recovery requirements should be agreed as part of the system design. We make that distinction clear rather than implying that every file is covered by a database restore.

06

Does this make the system compliant with every regulation?

No technology platform can make a business compliant by itself. Security controls support good governance, but compliance also depends on what information you collect, why you collect it, who has access, how long it is retained and how your team works.

During discovery we identify sensitive workflows and can design appropriate access, retention and audit requirements. Our organisational certification and core-platform testing provide a strong baseline; additional system-specific testing or legal assurance is scoped where the information or contractual requirements justify it.

Bring security into the first conversation

Tell us what information the system will hold, who needs access and which obligations matter to your business. We can then design the workflow and its safeguards together, rather than trying to retrofit security later.

Start your free Business Operations Review

Your information stays confidential. We are happy to sign an NDA before any detailed discussion.