ConsultCloud Security Policy
Last updated: 27 June 2026
ConsultCloud takes the security of customer data seriously. This statement describes the controls we operate today across the ConsultCloud application and the supporting infrastructure. Security is a shared responsibility: customers are responsible for account hygiene, user provisioning, role assignment and the integrations they choose to connect.
1. Hosting and platform
ConsultCloud is delivered as a cloud application running on managed infrastructure operated by a third-party platform host. The platform host provides the underlying compute, managed database, authentication and edge runtime, with controls covering physical security, network isolation, encryption, identity and incident response. ConsultCloud inherits those platform controls for the components our host operates and adds its own controls at the application layer. ConsultCloud is not itself separately certified and does not claim certifications held by our host.
2. Encryption
- All traffic to the application is encrypted in transit using TLS 1.2 or higher.
- Customer data at rest in our managed database is encrypted using industry-standard algorithms.
- Secrets and API keys are stored in a dedicated secrets manager and not in source control.
3. Access control
- Access to production systems is limited to a small number of authorised engineers on a need-to-know basis.
- Administrative access requires unique credentials and multi-factor authentication.
- Within the application, customers can assign roles to their own users and revoke access at any time.
- Row-level access controls keep each tenant's data logically isolated.
4. Authentication
User authentication is handled by a managed identity provider with hashed credentials, brute-force protection and session controls. Customers may sign in using email and password or supported single sign-on options where available.
5. Application security
- Code is reviewed before being merged to the main branch.
- Automated dependency scanning monitors for known vulnerabilities.
- Server-side validation, parameterised queries and output encoding mitigate common web risks.
- Material changes go through staged release with the ability to roll back.
6. Monitoring and logging
Application logs, access logs and security-relevant events are collected centrally. Anomalies such as repeated failed sign-ins or unusual application activity trigger alerts to the engineering team.
7. Backups and continuity
The production database is backed up automatically by the managed database provider with point-in-time recovery. Backups are retained for a rolling window sufficient to recover from operational incidents.
8. Subprocessors
ConsultCloud relies on a small number of subprocessors to deliver the Services: our platform host (hosting, managed database, authentication and edge compute), payment processing, e-signature, AI model providers, and customer-initiated integrations such as HubSpot and Xero which are only connected when a customer chooses to enable them. An up-to-date list and a copy of our Data Processing Agreement are available on request. .
9. Incident response
We maintain a documented incident response process. In the event of a confirmed security incident affecting customer data, we will notify affected customers without undue delay and provide information on impact and remediation steps.
10. Customer responsibilities
- Choose strong unique passwords and enable multi-factor authentication where available.
- Promptly remove users who no longer need access.
- Review integrations and revoke any that are no longer required.
- Avoid uploading data you are not entitled to share.
11. Reporting a vulnerability
If you believe you have found a security issue affecting ConsultCloud, please with as much detail as possible so we can investigate. We appreciate responsible disclosure.