Frequently Asked Questions
This section is divided into a number of subheadings to help you browse to the answers you are looking for.
Is my data secure on the internet?
Security from EmployeesSecurity from Hackers
Security in transmission
Backups and Resilience
Pricing
How do you manage what users can do?Are there any other costs?
Product
Why don't you offer an online free trial?How easy is it to change a system that is running?
Can it talk to other systems?
Is my data secure on the internet?
Security from Employees Heading> Top>>
The vast majority of security breaches and data theft is undertaken by disgruntled employess or recent ex-employees. Since you have already given them trusted access to your data, there is little that you can do to control any abuse of that access. With conventional systems and records such abuse is almost untraceable. Our systems have several levels of defences:- Security Groups: All users are assigned to specific security groups, and access to areas of the system is restricted to members of authorised security groups. You can therefore control what information each employees can see.
- Login Expiry: Every authorised user account has a defined expiry date, and can also be switched off immediately if required. You can therefore immediately switch off access at any time with a simple click of a mouse.
- Detailed Audit Trail: Because the system maintains a full audit trail, in the event that you have reason to suspect inappropriate use of your information, you can interrogate the records to establish exactly what information a particular user has accessed.
- IP Address Record: Every user login to the system records the IP address (i.e. where on the internet) from which the user is contacting the system. Thus it is possible to see if employees are accessing records from their home PC where this is not a normal part of their role.
Security from Hackers Heading> Top>>
Our systems are written in accordance with current Best Practice standards for secure development. We undertake vulnerability testing at all stages of development, and run regular automated test tools to ensure security is maintained. The specific details of the different attack risks and measures taken to neutralise them are outside the scope of this note, although we should be delighted to answer any specific questions you may have.Security in transmission Heading> Top>>
All customer systems operate under SSL encryption standard, from our third-party certified servers. This ensures that the connection between the user's browser and the server is encrypted so that the content of the information passed between them remains secure.Backups and Resilience Heading> Top>>
We maintain real-time backups by "mirroring" all communications to a second server in a remote datacentre. This ensures that, in the event of a complete loss of the primary datacentre, customers could be redirected to the backup servers within a matter of minutes.There is no need for any delay in restoring backups, since the backup server is updated in real time. In addition to this, each server runs redundant hard disc arrays and all databases are backed up on an automatic schedule. If for any reason it were necessary to restore a customer system from these backups, our tested time to recovery is less than one hour.

