H5Hi5CentralIT Operations Platform
Security designed in

Trust is part of the architecture.

Hi5Central is being built around tenant-aware access, strong identity, secure sessions, accountable administration and clear operational boundaries.

MFA-ready authenticationTenant-aware controlsAuditable administration
H5Security Core
IdentityTenantAuditEncryptSession

Protection at every layer of the platform.

Security is treated as a connected system of identity, authorisation, isolation, observability and infrastructure controls.

Identity first

Strong authentication, MFA, secure recovery, session management and enterprise identity integrations.

Tenant isolation

Every organisation is resolved, authorised and audited within its own tenant-aware security boundary.

Complete accountability

Administrative, authentication and operational actions are recorded with actor, time, result and context.

Encrypted communications

Public services use HTTPS, secure cookies and protected application-to-service connections.

Tenant-aware architecture

Every request must prove who, where and what.

A signed-in user is not automatically authorised everywhere. Protected operations are evaluated against the identity, active tenant membership, role, permission and requested resource.

01Resolve the workspaceThe requested company subdomain identifies the tenant context.
02Validate the sessionThe session must be active, unexpired and associated with the expected identity.
03Confirm membershipThe user must hold an active membership within the resolved organisation.
04Authorise the operationRoles and permissions determine whether the action is allowed.
Protected requestAuthorisation flow
01
acme.hi5central.comWorkspace resolved
Verified
02
Secure sessionIdentity and expiry checked
Active
03
Tenant membershipOrganisation access checked
Member
04
Permission decisionRequested capability evaluated
Allowed
Secure workspace accessMulti-factor authentication
481392
Authenticator code verified
Current sessionLondon, United Kingdom
Active now
Identity protection

Strong authentication without unnecessary friction.

Hi5Central authentication is being designed around secure passwords, MFA, recovery controls, session visibility and enterprise identity integration.

Authenticator-app MFARecovery codesSecure password hashingLogin attempt protectionSession expiry and revocationRemembered-device controlsSAML and OIDC roadmapSCIM provisioning roadmap

Defence in depth, not dependence on one control.

Application security is reinforced by explicit permissions, protected deployment secrets and infrastructure-level boundaries.

01

Role-based access control

Permissions will be assigned through roles, groups and explicit administrative capabilities rather than broad all-or-nothing access.

02

Tenant-aware authorisation

API requests are evaluated against both the authenticated identity and the selected organisation before protected data is returned.

03

Secure session cookies

Authentication sessions use protected HTTP-only cookies with secure transport and controlled lifetimes.

04

Auditable administration

Security-sensitive configuration changes are designed to create durable audit records.

05

Secret separation

Database, encryption, SMTP, DNS and application credentials remain outside source control and are supplied at deployment time.

06

Defence in depth

Application controls are combined with reverse-proxy security headers, firewall rules, service isolation and intrusion protection.

Accountability

Important actions leave an operational trail.

Audit events are designed to capture who acted, what changed, which organisation was affected, whether the action succeeded and when it occurred.

Successful and failed sign-insMFA enrolment and removalPassword and recovery changesUser invitations and access changesRole and permission updatesSession revocationTenant setting changesFuture remote-session activity
Security activityLive audit preview
User signed in with MFADaniel Sutton · 19:42:18
Success
Session revoked by administratorSecurity settings · 19:31:04
Completed
!
Failed sign-in attemptUnknown device · 19:24:51
Blocked
Role permissions updatedPlatform administrators · 18:58:22
Success

Security controls that follow the platform.

The same security principles apply whether Hi5Central is operated as a managed cloud service or deployed into customer-controlled infrastructure.

Managed cloud

Hi5Central manages the application stack, certificate lifecycle, infrastructure updates, service monitoring and platform backup processes.

Managed TLS certificatesPrivate application networksDatabase and cache isolationControlled infrastructure accessAutomated operational monitoring

Self-hosted

Customer-controlled deployments retain the core application security model while allowing organisations to own network, storage, backup and infrastructure policy.

Infrastructure ownershipCustomer-managed network controlsInternal backup policyControlled update windowsPrivate data residency
Future RMM security

Remote access will be treated as a privileged operation.

Remote support is not yet part of this new ITSM build. The future RMM design will use explicit session creation, short-lived access material, authenticated agents, transport encryption and detailed activity records.

Authenticated session requestsShort-lived connection materialAuthorised technician accessSession activity historySecure signalling and transportAdministrative policy controls
Remote support requestFuture capability
PC
FIN-LAPTOP-024Windows 11 · Finance
Online
TechnicianDaniel Sutton
Access levelInteractive support
Session expiry10 minutes

Progress communicated without overstating readiness.

Security claims will be published carefully. Planned controls and assurance work will remain clearly distinguished from completed certification.

01
FoundationIn development

Security architecture

Tenant-aware authentication, MFA, secure sessions, role-based access and audit foundations.

02
LaunchPlanned

Operational controls

Security dashboards, session management, retention controls, exportable audit history and administrative policies.

03
EnterpriseRoadmap

Identity and governance

SSO, SCIM, conditional-access options, expanded retention controls and dedicated enterprise security tooling.

04
AssuranceRoadmap

Formal compliance

Security assurance and certification work will be published only after the relevant programmes are formally underway or complete.

Important

Hi5Central will not claim SOC 2, ISO 27001, Cyber Essentials or other formal certification unless that certification has actually been completed and publicly confirmed.

Responsible disclosure

Found a potential security issue?

Please report suspected vulnerabilities privately. Do not include unnecessary personal data, credentials or customer information. A dedicated disclosure process will be published before launch.

Contact the security teamFor testing only. A dedicated security address will be added before production launch.

Understand the controls and the roadmap.

Clear answers about the current platform design and planned enterprise security capabilities.

Does Hi5Central support multi-factor authentication?

MFA is part of the core authentication design. Authenticator applications and recovery codes are planned as the initial methods, with additional enterprise identity options on the roadmap.

How are organisations separated?

Hi5Central uses tenant-aware routing, data relationships and authorisation checks. A valid identity must also hold an active membership in the requested organisation.

Will audit logs be available to customers?

Yes. Authentication, administrative and operational activity is being designed around durable audit events that can later be searched, filtered and exported according to plan and retention settings.

Can Hi5Central be self-hosted?

Self-hosted deployment is part of the product direction. Organisations choosing that model will control the infrastructure while using the same core application architecture.

Is Hi5Central currently certified to a compliance standard?

No certification should be assumed unless it is explicitly published as completed. Compliance items shown on the site are roadmap intentions rather than current certifications.

How will remote support be secured?

Remote support is a future RMM capability. The design direction includes authenticated session creation, explicit authorisation, short-lived access material, transport encryption and detailed activity records.

Secure from the foundation

Build your service platform on a security-first foundation.

Create your workspace and follow the platform as its authentication, governance and audit capabilities move toward launch.