Multi-Factor Authentication
MFA is implemented for platform users and mandatory for privileged accounts.
CommsPliant uses technical and operational controls to protect access, separate customer environments, monitor the service and manage security events.
The controls below describe what is implemented today and how those controls are supported by documented procedures, testing and evidence.
MFA is implemented for platform users and mandatory for privileged accounts.
Permissions are enforced in the application backend so users can only perform actions allowed by their role.
Production access is deliberately restricted and maintained through a controlled privileged-access process.
User access can be removed immediately when it is no longer required.
Organisation and tenant boundaries are enforced server-side rather than relying only on what the user interface displays.
External application traffic is protected using HTTPS/TLS.
Production secrets are stored in environment configuration rather than source code.
Security and audit events are logged, with Prometheus, Grafana and Loki supporting monitoring and operational visibility. Infrastructure and server performance are monitored continuously.
Normal access logging follows a metadata-first approach. Full customer templates, rendered outputs, passwords, tokens and secrets are not intentionally written to normal access logs.
CommsPliant performs recurring internal security testing covering:
Third-party automated vulnerability scanning is planned as the next external assurance step.
A documented Incident Response and Personal Data Breach Procedure defines how security incidents are assessed, contained, escalated and managed.
A suspicious-login and traffic-flood tabletop exercise was completed on 25 August 2026 with a pass result.
Product changes follow a documented change-control process covering normal, material/high-risk and emergency changes.
Development and test resources are separated from production, synthetic or dummy data is preferred for testing, and rollback and recovery considerations are included where relevant.
The following supporting documents are maintained by CommsPliant.
| Resource | Availability | Action |
|---|---|---|
| Information Security Policy |
|
Request access |
| Access Control and Privileged Access Policy |
|
Request access |
| Logging and Security Monitoring Standard |
|
Request access |
| Change Management and Secure Development Procedure |
|
Request access |
| Incident Response and Personal Data Breach Procedure |
|
Request access |
| Internal Security Testing Programme |
|
Request access |
| Privileged Access Register |
|
Request access |
| ISO 27001 Evidence Register |
|
Request access |
Sensitive implementation detail and internal evidence are available only where appropriate during security or procurement review. A request does not guarantee that the full internal document will be shared; where appropriate, CommsPliant may provide a client-facing version, extract, summary or controlled evidence instead.
Yes. Multi-factor authentication is implemented for platform users and is mandatory for privileged accounts.
Organisation and tenant boundaries are enforced server-side rather than relying only on what the user interface displays.
CommsPliant uses role-based access control, with permissions enforced in the application backend. Privileged production access is deliberately restricted and managed through a controlled privileged-access process.
Yes. CommsPliant performs recurring internal security testing covering vulnerability assessment, authentication and brute-force testing, traffic and DDoS-resilience testing, and additional scheduled or ad hoc checks. Third-party automated vulnerability scanning is planned as the next external assurance step.
If you need more detail about CommsPliant's security controls, testing or supporting evidence, contact us and we'll help.
Request more information