Security built into the platform.

CommsPliant uses technical and operational controls to protect access, separate customer environments, monitor the service and manage security events.

The controls below describe what is implemented today and how those controls are supported by documented procedures, testing and evidence.

Only the right people can do the right things.

Multi-Factor Authentication

MFA is implemented for platform users and mandatory for privileged accounts.

Implemented

Role-Based Access Control

Permissions are enforced in the application backend so users can only perform actions allowed by their role.

Implemented

Privileged Access

Production access is deliberately restricted and maintained through a controlled privileged-access process.

Implemented

Access Removal

User access can be removed immediately when it is no longer required.

Implemented

Customer environments are separated by design.

Organisation and tenant boundaries are enforced server-side rather than relying only on what the user interface displays.

Implemented

Secure Traffic & Secrets

Data in transit

External application traffic is protected using HTTPS/TLS.

Implemented

Secrets management

Production secrets are stored in environment configuration rather than source code.

Implemented

We monitor the system, not just the paperwork.

Security and audit events are logged, with Prometheus, Grafana and Loki supporting monitoring and operational visibility. Infrastructure and server performance are monitored continuously.

Normal access logging follows a metadata-first approach. Full customer templates, rendered outputs, passwords, tokens and secrets are not intentionally written to normal access logs.

Operational

Security Testing

CommsPliant performs recurring internal security testing covering:

  • vulnerability assessment
  • authentication and brute-force testing
  • traffic and DDoS-resilience testing
  • scheduled and additional ad hoc checks
Recurring

Third-party automated vulnerability scanning is planned as the next external assurance step.

Next step

Incident Response

A documented Incident Response and Personal Data Breach Procedure defines how security incidents are assessed, contained, escalated and managed.

A suspicious-login and traffic-flood tabletop exercise was completed on 25 August 2026 with a pass result.

Tested

Secure Development & Change Management

Product changes follow a documented change-control process covering normal, material/high-risk and emergency changes.

Development and test resources are separated from production, synthetic or dummy data is preferred for testing, and rollback and recovery considerations are included where relevant.

Documented and operating

Security Resources

The following supporting documents are maintained by CommsPliant.

Resource Availability Action
Information Security Policy On request Request access
Access Control and Privileged Access Policy Controlled Request access
Logging and Security Monitoring Standard Controlled Request access
Change Management and Secure Development Procedure Controlled Request access
Incident Response and Personal Data Breach Procedure Controlled Request access
Internal Security Testing Programme Controlled Request access
Privileged Access Register Controlled Request access
ISO 27001 Evidence Register Controlled Request access

Sensitive implementation detail and internal evidence are available only where appropriate during security or procurement review. A request does not guarantee that the full internal document will be shared; where appropriate, CommsPliant may provide a client-facing version, extract, summary or controlled evidence instead.

Security FAQ

Still have questions?

If you need more detail about CommsPliant's security controls, testing or supporting evidence, contact us and we'll help.

Request more information