Security and trust
Built to pass the review that kills most vendors
This page is for the IT manager and the procurement reviewer. Every claim below is qualitative on purpose: the exact parameters belong in a security conversation, not on a public page. The short version: per-device cryptographic identity, signed messaging, MFA, and instant revocation, with no shared passwords anywhere on site hardware.
Site Commander is cloud access control without an on-premise server. Every device holds its own cryptographic identity and is approved by an administrator, all hardware messaging is signed and replay-protected, accounts use MFA and automatic lockout, and apps ship as signed builds with staged silent updates.
Devices
Every device proves who it is
Workstations, kiosks and gate controllers are individually enrolled, individually approved and individually revocable. There are no shared passwords anywhere on site hardware.
Hardware-bound identity
Each device enrols with an admin-issued code and generates its own key pair on the device. iPad private keys never leave the Apple Keychain.
Admin approval required
A newly enrolled device can do nothing until an administrator approves it. Unapproved devices are blocked automatically after a waiting period.
Attestation on every launch
Devices prove possession of their key by signing a fresh challenge from the platform on every boot. No cached trust, no shared API keys to leak.
Instant remote revocation
A lost or compromised device is blocked from the console and locks immediately with a dead-end screen.
In transit
Messages that cannot be forged or replayed
The conversation between your gates, kiosks and the platform is signed in both directions.
PKI-signed messaging
Every message between hardware and the platform is cryptographically signed both ways and verified before it is acted on.
Replay protection
Messages are timestamp-checked and replay-protected, so a captured message cannot be re-sent to open a gate.
Offline integrity
Scans queued by an offline gate are replayed as a signed batch and processed in order, so a network drop never becomes a data integrity problem.
People
Accounts that hold the line
Standard, boring, correct account security, present everywhere it should be.
Multi-factor authentication
TOTP-based MFA, enforced for site administrators and mandatory for every platform admin login.
Automatic account lockout
Repeated failed logins lock the account automatically, with the same protection applied to device enrolment codes.
Default-deny permissions
Forty-five granular permissions across seven roles, enforced on every platform endpoint, with sessions protected by rolling renewal, CSRF protection and logout-everywhere.
Software
Apps that stay current by themselves
The deployment burden on your IT team rounds to zero.
Hardened, signed builds
Desktop apps are sandboxed and context-isolated with a strict content security policy, and Windows installers are signed.
Staged silent updates
Apps update themselves automatically with staged percentage rollouts and stable and beta channels. Nobody walks round the site with a USB stick.
Minimum version enforcement
Outdated clients are refused by the platform, so no stale app ever touches production data.
Privacy
Personal data treated like it matters
Privacy by design, visible in the details.
Masked public pages
Visitor confirmation pages mask personal details, so a forwarded email never overshares.
A no-tracker visitor portal
No analytics, no advertising trackers and no third-party scripts on the public visitor form.
Managed policy content
Privacy and cookie policy content is platform-managed and rendered wherever visitors interact with the system.
FAQ
Questions IT and procurement ask
For IT and procurement
Bring your security questionnaire.
Book a walkthrough for your technical team. We will cover device identity, signed messaging, account controls and update delivery, in as much depth as your review needs.
Book a security walkthrough