Identity first
Strong authentication, MFA, secure recovery, session management and enterprise identity integrations.
Hi5Central is being built around tenant-aware access, strong identity, secure sessions, accountable administration and clear operational boundaries.
Security is treated as a connected system of identity, authorisation, isolation, observability and infrastructure controls.
Strong authentication, MFA, secure recovery, session management and enterprise identity integrations.
Every organisation is resolved, authorised and audited within its own tenant-aware security boundary.
Administrative, authentication and operational actions are recorded with actor, time, result and context.
Public services use HTTPS, secure cookies and protected application-to-service connections.
A signed-in user is not automatically authorised everywhere. Protected operations are evaluated against the identity, active tenant membership, role, permission and requested resource.
Hi5Central authentication is being designed around secure passwords, MFA, recovery controls, session visibility and enterprise identity integration.
Application security is reinforced by explicit permissions, protected deployment secrets and infrastructure-level boundaries.
Permissions will be assigned through roles, groups and explicit administrative capabilities rather than broad all-or-nothing access.
API requests are evaluated against both the authenticated identity and the selected organisation before protected data is returned.
Authentication sessions use protected HTTP-only cookies with secure transport and controlled lifetimes.
Security-sensitive configuration changes are designed to create durable audit records.
Database, encryption, SMTP, DNS and application credentials remain outside source control and are supplied at deployment time.
Application controls are combined with reverse-proxy security headers, firewall rules, service isolation and intrusion protection.
Audit events are designed to capture who acted, what changed, which organisation was affected, whether the action succeeded and when it occurred.
The same security principles apply whether Hi5Central is operated as a managed cloud service or deployed into customer-controlled infrastructure.
Hi5Central manages the application stack, certificate lifecycle, infrastructure updates, service monitoring and platform backup processes.
Customer-controlled deployments retain the core application security model while allowing organisations to own network, storage, backup and infrastructure policy.
Remote support is not yet part of this new ITSM build. The future RMM design will use explicit session creation, short-lived access material, authenticated agents, transport encryption and detailed activity records.
Security claims will be published carefully. Planned controls and assurance work will remain clearly distinguished from completed certification.
Tenant-aware authentication, MFA, secure sessions, role-based access and audit foundations.
Security dashboards, session management, retention controls, exportable audit history and administrative policies.
SSO, SCIM, conditional-access options, expanded retention controls and dedicated enterprise security tooling.
Security assurance and certification work will be published only after the relevant programmes are formally underway or complete.
Hi5Central will not claim SOC 2, ISO 27001, Cyber Essentials or other formal certification unless that certification has actually been completed and publicly confirmed.
Please report suspected vulnerabilities privately. Do not include unnecessary personal data, credentials or customer information. A dedicated disclosure process will be published before launch.
Clear answers about the current platform design and planned enterprise security capabilities.
MFA is part of the core authentication design. Authenticator applications and recovery codes are planned as the initial methods, with additional enterprise identity options on the roadmap.
Hi5Central uses tenant-aware routing, data relationships and authorisation checks. A valid identity must also hold an active membership in the requested organisation.
Yes. Authentication, administrative and operational activity is being designed around durable audit events that can later be searched, filtered and exported according to plan and retention settings.
Self-hosted deployment is part of the product direction. Organisations choosing that model will control the infrastructure while using the same core application architecture.
No certification should be assumed unless it is explicitly published as completed. Compliance items shown on the site are roadmap intentions rather than current certifications.
Remote support is a future RMM capability. The design direction includes authenticated session creation, explicit authorisation, short-lived access material, transport encryption and detailed activity records.
Create your workspace and follow the platform as its authentication, governance and audit capabilities move toward launch.