Security
FoxDesk Cloud uses layered organisational and technical safeguards appropriate to a hosted business helpdesk and time-reporting service.
Account and access protection
We use role-based access, least privilege, password hashing, protected sessions, optional multi-factor authentication, revocable API tokens and administrative audit records. Customers control their own users and should remove access promptly, protect devices and credentials, and restrict administrator roles.
Tenant separation
Customer requests and data access are bound to the authenticated workspace. We test tenant boundaries on high-risk notification, email, API, reporting and administration paths and treat cross-workspace access as a security incident.
Transport, storage and secrets
Connections to the production service use encrypted transport. Operational secrets are separated from source code and access is limited. Attachments, exports and backups are handled through controlled service paths. Customers should not use tickets or files to store passwords, complete card data or unnecessary highly sensitive data.
Operations and recovery
We use controlled releases, health checks, logging, monitoring, dependency and vulnerability review, database backup and restore testing, and incident procedures. Production database backups currently use a verified 14-day rotation. Recovery objectives are operational targets, not a guarantee that every failure or data loss can be prevented.
Incident response
We investigate credible security events, contain affected access, preserve appropriate evidence, remediate the cause, and notify affected customers or authorities when legally required. Processor breach notices follow the DPA and may be updated in phases as facts become available.
Customer responsibilities
Customers remain responsible for lawful content, user lifecycle, endpoint security, account permissions, safe integration design, exports needed for their continuity, and promptly reporting suspected compromise. Security, abuse and automation limits may temporarily restrict a risky action while leaving ordinary reading and export available where safe.
Vulnerability reporting
Report a suspected vulnerability privately to [email protected] with the affected URL, reproducible steps, expected impact and non-sensitive evidence. Do not access another customer’s data, persist access, disrupt service, run denial-of-service tests, or disclose a vulnerability before we have a reasonable opportunity to investigate and remediate.
Nothing in these documents excludes a statutory duty, remedy, or right that applicable mandatory law does not permit the parties to exclude or limit.