Skip to main content

Third-party tests

Cloud security

This section explains how the product performs against the NCSC Cloud Security Principles.

1. Data encryption

Data in transit

Data at rest

2. Authentication and access control

Sign-in options

Privilege separation

User accounts are separated into three levels of privilege:

3. Security logging and incident management

Logging and event collection

The service records an audit log of all changes and important events, including account lockout and disabling two-factor authentication.

Availability of logs

Logs are available to administrators using the Audit History link in the app's navigation bar.

Incident response process

The service has a documented incident response process with identified responsibilities.

Personal data breaches are reported to the UK Information Commissioner's Office (ICO) within 72 hours where required, and affected customers are notified without undue delay.

Vulnerability scanning

The service is regularly scanned by an independent external vulnerability scanning service.

Security updates

Scheduled platform security updates are applied as soon as they're available on the second Tuesday of each month (Patch Tuesday). Unscheduled platform security updates (out-of-band updates) are also applied as soon as they're available.

Vulnerability disclosure process

All reports of security issues should use the process described in the vulnerability disclosure policy referenced in our security.txt file.

4. Governance

Privacy policy

Our privacy policy explains how data is processed.

Data location and legal jurisdiction

Data is processed and stored in Azure data centers based in the UK. PowerMapper Software Ltd is registered with the UK Information Commissioner's Office (registration Z2071300).

Data retention and deletion

Resilience and backups

Secure development

Scanner IP addresses

Scans run from a published set of IP addresses, listed in Technote TN-Q12, so your security team can identify or allowlist scan traffic.

Product security features

The following security features are available by default with no additional configuration: