Security

CRM security that stands up to scrutiny

Being secure from the growing threat of cyber attacks is a significant part of CommTrak’s goals. We have a complex and broad array of applications and hardware we use to make it possible to achieve that goal. Our customers also entrust us with some of their most sensitive information that they rely on day to day. We strive to take the most important measures to make sure our IT environment remains as secure as possible from the increasing array of cyber threats.

Your Data

CommTrak provides Australian-based hosting in world class AWS data centres.

Each customer using CommTrak has their own dedicated database, isolated from any other customers’ CommTrak interactions.

All data is encrypted at rest in accordance with our Cyber Security Policy.

Access & Authentication

IP-Based Permissions
Restrict access to CommTrak to within a physical building or location using IP-based whitelisting.
Password Complexity Controls
Minimise the chance of brute force attacks or data breaches by increasing the mandatory complexity of users’ passwords.
Two-Factor Authentication (2FA)
Add an extra step to the login process. 2FA requires a unique code as well as a password, with three ways to receive it: SMS, email, or an authenticator app.
Single Sign-On (SSO)
Let staff sign in with your existing identity provider, so access is granted and revoked centrally alongside every other system they use.
Session Timeouts
Idle sessions are closed automatically, so an unattended machine does not leave CommTrak open to whoever walks past it.
Invalid Attempt Lockouts
Repeated failed logins lock the account, shutting down password-guessing attacks before they get anywhere.
Maximum Session Lifetime
A hard ceiling on how long any session can live, so access is re-authenticated rather than left open indefinitely.

CommTrak Permissions

No longer will you have to worry about giving the wrong people access to sensitive information – set permission restrictions for specific features, modules, reports and customers, and assign them at the user level or in bulk, using staff role security settings.

Extensive staff activity reporting is also available, to assist with performance coaching and assessing security concerns.

See Security on your own data

Book a demo and we’ll show this module against the way your business actually works.