Site Commander

Security and trust

Built to pass the review that kills most vendors

This page is for the IT manager and the procurement reviewer. Every claim below is qualitative on purpose: the exact parameters belong in a security conversation, not on a public page. The short version: per-device cryptographic identity, signed messaging, MFA, and instant revocation, with no shared passwords anywhere on site hardware.

Site Commander is cloud access control without an on-premise server. Every device holds its own cryptographic identity and is approved by an administrator, all hardware messaging is signed and replay-protected, accounts use MFA and automatic lockout, and apps ship as signed builds with staged silent updates.

Devices

Every device proves who it is

Workstations, kiosks and gate controllers are individually enrolled, individually approved and individually revocable. There are no shared passwords anywhere on site hardware.

Hardware-bound identity

Each device enrols with an admin-issued code and generates its own key pair on the device. iPad private keys never leave the Apple Keychain.

Admin approval required

A newly enrolled device can do nothing until an administrator approves it. Unapproved devices are blocked automatically after a waiting period.

Attestation on every launch

Devices prove possession of their key by signing a fresh challenge from the platform on every boot. No cached trust, no shared API keys to leak.

Instant remote revocation

A lost or compromised device is blocked from the console and locks immediately with a dead-end screen.

In transit

Messages that cannot be forged or replayed

The conversation between your gates, kiosks and the platform is signed in both directions.

PKI-signed messaging

Every message between hardware and the platform is cryptographically signed both ways and verified before it is acted on.

Replay protection

Messages are timestamp-checked and replay-protected, so a captured message cannot be re-sent to open a gate.

Offline integrity

Scans queued by an offline gate are replayed as a signed batch and processed in order, so a network drop never becomes a data integrity problem.

People

Accounts that hold the line

Standard, boring, correct account security, present everywhere it should be.

Multi-factor authentication

TOTP-based MFA, enforced for site administrators and mandatory for every platform admin login.

Automatic account lockout

Repeated failed logins lock the account automatically, with the same protection applied to device enrolment codes.

Default-deny permissions

Forty-five granular permissions across seven roles, enforced on every platform endpoint, with sessions protected by rolling renewal, CSRF protection and logout-everywhere.

Software

Apps that stay current by themselves

The deployment burden on your IT team rounds to zero.

Hardened, signed builds

Desktop apps are sandboxed and context-isolated with a strict content security policy, and Windows installers are signed.

Staged silent updates

Apps update themselves automatically with staged percentage rollouts and stable and beta channels. Nobody walks round the site with a USB stick.

Minimum version enforcement

Outdated clients are refused by the platform, so no stale app ever touches production data.

Privacy

Personal data treated like it matters

Privacy by design, visible in the details.

Masked public pages

Visitor confirmation pages mask personal details, so a forwarded email never overshares.

A no-tracker visitor portal

No analytics, no advertising trackers and no third-party scripts on the public visitor form.

Managed policy content

Privacy and cookie policy content is platform-managed and rendered wherever visitors interact with the system.

FAQ

Questions IT and procurement ask

For IT and procurement

Bring your security questionnaire.

Book a walkthrough for your technical team. We will cover device identity, signed messaging, account controls and update delivery, in as much depth as your review needs.

Book a security walkthrough