Security
Platform Security Principles
Last updated 23 March 2026
Platform and organisational security is maintained through a combination of technical controls at the infrastructure level and organisational measures governing how staff operate.
Technical Controls
- Data in transit is encrypted via TLS
- Login credentials are protected using AES encryption
- A software firewall is in place at the server level
- Malware scanning runs continuously with automatic removal of known threats
- Known bots are blocked at the network edge
- Mod Security enterprise ruleset is applied for additional protection
- Tenant isolation is enforced through Docker containerisation
Organisational Controls
- All staff operate under a formal Information Security Policy
- Strong 14-character passwords are required, managed via 1Password
- Two-factor authentication is enabled across systems where available
- All devices are auto-locked when unattended
- Staff receive data protection and information security training at induction and at regular intervals
- Cyber and data security insurance is maintained
- A formal risk assessment process is maintained, with a risk register reviewed regularly
Legal responsibility for the content on this page sits with 3manfactory Ltd.