Third-party tests
- app.powermapper.com scores A+ on Mozilla Observatory
- app.powermapper.com scores A+ on securityheaders.com
- app.powermapper.com scores A+ on SSL Labs tests
Cloud security
This section explains how the product performs against the NCSC Cloud Security Principles.
1. Data encryption
Data in transit
- Data in transit is encrypted using TLS 1.2 (TLS 1.1 and earlier is disabled)
- Certificate issuance is limited by DNS CAA records
- Certificates are managed by LetsEncrypt and rotated every 60 days
- HSTS is used with max-age set to 12 months
- HTTP requests are redirected to HTTPS
- TLS ciphers marked as weak by SSLLabs are disabled
Data at rest
- Data at rest is encrypted using AES 256
- Credentials supplied for authenticated scans are stored encrypted, never in plain text, with support for key rotation
- Application data protection keys are encrypted with a key held in Azure Key Vault
2. Authentication and access control
Sign-in options
- Two-factor authentication (2FA) uses authenticator apps (TOTP) with single-use backup codes
- Sign-in attempts are rate limited per IP address, and login timing is randomized to resist account enumeration and brute force attacks
- SAML single sign-on (SSO) is available in the on-premises Enterprise edition
Privilege separation
User accounts are separated into three levels of privilege:
- Administrators who can create or delete users, and can access billing details
- Standard User who can create or delete scan reports
- Read-only User who can only view scan reports
3. Security logging and incident management
Logging and event collection
The service records an audit log of all changes and important events, including account lockout and disabling two-factor authentication.
Availability of logs
Logs are available to administrators using the Audit History link in the app's navigation bar.
Incident response process
The service has a documented incident response process with identified responsibilities.
Personal data breaches are reported to the UK Information Commissioner's Office (ICO) within 72 hours where required, and affected customers are notified without undue delay.
Vulnerability scanning
The service is regularly scanned by an independent external vulnerability scanning service.
Security updates
Scheduled platform security updates are applied as soon as they're available on the second Tuesday of each month (Patch Tuesday). Unscheduled platform security updates (out-of-band updates) are also applied as soon as they're available.
Vulnerability disclosure process
All reports of security issues should use the process described in the vulnerability disclosure policy referenced in our security.txt file.
4. Governance
Privacy policy
Our privacy policy explains how data is processed.Data location and legal jurisdiction
Data is processed and stored in Azure data centers based in the UK. PowerMapper Software Ltd is registered with the UK Information Commissioner's Office (registration Z2071300).
Data retention and deletion
- Scan data is deleted 6 weeks after subscription cancellation
- Account data (name, email, company) is anonymized 3 years after cancellation
- Each customer's scans and reports are only visible to that customer's users - queries are scoped to the customer account
Resilience and backups
- Databases are geo-replicated between two UK Azure regions with automatic failover, and backed up
- The web app runs on servers in multiple data centers behind Azure Traffic Manager, which routes around a failed server or data center automatically
- Failover is exercised every month as servers cycle through scheduled maintenance
Secure development
- Code changes are reviewed against the OWASP secure coding checklist
- Third-party dependencies are pinned to exact versions and verified against the package repository's signatures before builds
- Releases are code signed and rolled out in stages, starting with canary servers
Scanner IP addresses
Scans run from a published set of IP addresses, listed in Technote TN-Q12, so your security team can identify or allowlist scan traffic.
Product security features
The following security features are available by default with no additional configuration:
- Password strength is checked when passwords are changed
- Changed passwords are checked against the 100,000 most common passwords, using the NCSC list derived from the Have I Been Pwned data set
- Audit log shows security incidents (failed logins, password resets, etc)
- Anti-CSRF tokens are used on all form POSTs (including login)
- Passwords are hashed by PBKDF2
- Two-factor authentication (2FA) is available for all user accounts
- DDoS protection is provided by Azure