Article

How Secure Is the Virtual Cabinet Portal?

This article explains how the Virtual Cabinet Portal is secured, including encryption standards, data centre infrastructure, penetration testing, and auditing.

Overview

The Virtual Cabinet Portal is built to the highest industry security standards, using the same methods and principles applied by banks and government bodies. Documents stored in the Portal are, in most cases, more secure than those held on your own systems, with 99.9% uptime and 24/7 availability.

 

ISO 27001 Compliance

The Virtual Cabinet Portal is ISO 27001 compliant. The security of the application, including how it is designed, built, tested, and maintained, is our highest priority. We stringently aim to exceed industry standards.

 

Encryption

  • All data in transit to and from the Portal is encrypted using TLS.
  • Data, documents, and files stored in the Portal are hashed or encrypted using AES-256 where applicable.

 

Data Centres

The Portal is hosted on Amazon Web Services (AWS) infrastructure in the AWS EU (London) region. Encrypted data backups are stored in AWS EU (Ireland) to provide cross-region redundancy.

AWS treats security as its highest priority. Full details on their infrastructure, physical security, and network architecture are available at aws.amazon.com/security.

 

Penetration Testing

The Portal is secured behind multiple firewalls and has been hardened against attack methods including:

  • Brute force password attacks
  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF)
  • JSON hijacking
  • SQL injection

This hardening applies at every level of the application architecture and is tested internally by CREST-certified engineers, then verified by independent third-party security specialists.

 

Auditing

Every action performed within the Portal is logged and recorded against the individual who performed it, providing a complete and compliant audit trail.

Powered by Zendesk