Skip to content
SecurityOps
Menu

Security

SecurityOps holds evidence about your officers — photographs, location and licence details. This page sets out how that is protected. If you need this in a supplier questionnaire format, ask and we will complete yours.

Encryption

All traffic is served over TLS. Data is encrypted at rest by our database and object-storage providers. Evidence photos are served through short-lived signed URLs rather than public links.

Tenant isolation

Every record is scoped to your company. Isolation is enforced centrally in the API and covered by an automated test suite that asserts one company cannot read another company’s shifts, attendance, sites, users or reports.

Access control

Role-based access separates officers, company administrators and platform staff. Sessions are short-lived with server-side revocation, so removing an account takes effect immediately.

Backups

The database is backed up on a schedule to versioned, access-restricted storage, and restores are rehearsed rather than assumed.

Data retention

Evidence is retained for the period your contract requires and then removed. Tell us your retention requirement and we will confirm it in writing.

Monitoring

Application errors and availability are monitored continuously, with alerting on failure.

Reporting a vulnerability

Email security@securityops.co.uk. We acknowledge reports within two working days and will keep you updated until it is resolved. Please give us reasonable time to fix an issue before disclosing it.