Security by Design
The software includes multiple security features to ensure organisations have complete control over access to functionality and data. The comprehensive permissions area allows administrators to define which modules are available to users along with granular permissions for viewing, storing and deletion of data. Managers can monitor users' actions with full audit trails.
Client access to 'Experiences' can be secured with single sign on (AD integration), alternatively administrators may enforce strong passwords expiry and lock out if entered incorrectly. Users can also be restricted by IP and time lockdowns.
To protect data that is actively transmitted between networks and/or devices, Click4Assistance uses HTTPS/SSL on SHA-256 bit encryption for secure connections, in addition to encryption of data at rest.
Internal Security
Working within ISO27001:2022 framework with BSI accreditation, Click4Assistance operates clean desk policy, strong passwords and administrative restrictions along with many other stringent rules to ensure data security, some of which must remain confidential in order to protect the integrity of the policy.
During recruitment applications are reference and DBS checked, with security training delivered to all staff at induction and at regular intervals throughout their employment at Click4Assistance. All client data is considered highly sensitive therefore access is restricted to key technical staff. Database access requires unmemorable complex password entry which is changed regularly and can only be retrieved with director approval.
Development & Infrastructure
Security protocols are embedded into all operations from product development, infrustructure and the physical environment. Security aware software development with agile methodologies occurs under strict change control processes which require rigorous testing regimes and multiple sign off to OWASP standards before release.
Servers are located in London UK within Telecity (Europe’s most advanced data centre), who comply to a range of standards including ISO9001, ISO27001 and ISO22301. With Biometric access control and 24/7 CCTV and guards, every precaution is taken into account.