Data, privacy and security
Control GDPR, consent, exports, backups, audit logs, authentication and data retention.
Configure GDPR and consent purposes
Configure GDPR and consent purposesDefine consent purposes and enable the privacy tools required by the organisation.
Open guide →GuideRecord and review contact consent
Record and review contact consentCapture opt-in or opt-out evidence for configured consent purposes.
Open guide →GuideHandle a data removal request
Handle a data removal requestReview the request, assess linked records and update status using the organisation’s legal process.
Open guide →GuideExport CRM data
Export CRM dataGenerate supported data exports for portability, audit or controlled analysis.
Open guide →GuideCreate and restore database backups safely
Create and restore database backups safelyCreate, download, schedule and retain database backups according to an approved recovery policy.
Open guide →GuideReview the activity log
Review the activity logAudit important staff and system actions and clear logs only under an approved retention policy.
Open guide →GuideConfigure password, session and two-factor security
Configure password, session and two-factor securityApply strong authentication practices and understand session-clearing controls.
Open guide →GuideManage spam filters and blocked senders
Manage spam filters and blocked sendersReduce unwanted support traffic while avoiding over-broad rules that block valid customers.
Open guide →GuideSecure HR documents →
Open guide →GuideRetention and data governance →
Open guide →GuideCore CRM security hardening release overview
Core CRM security hardening release overviewUnderstand the complete security overlay, matched migrations and operational checks included in the core CRM update.
Open guide →GuideUse cryptographically secure public tokens
Use cryptographically secure public tokensUnderstand how public links and tokenised actions use secure unpredictable token generation.
Open guide →GuideUnderstand Argon2id password hashing
Understand Argon2id password hashingUnderstand the one-way password algorithm applied to newly created or changed credentials.
Open guide →GuideUnderstand transparent phpass password upgrading after login
Understand transparent phpass password upgrading after loginUnderstand how a valid legacy phpass password is re-hashed after successful authentication.
Open guide →GuideApply staff login throttling
Apply staff login throttlingUnderstand protection against repeated failed staff authentication attempts.
Open guide →GuideApply client login throttling
Apply client login throttlingUnderstand protection against repeated failed client-portal authentication attempts.
Open guide →GuideApply API request throttling
Apply API request throttlingUnderstand rate controls protecting authenticated and token-based API traffic.
Open guide →GuideApply two-factor authentication throttling
Apply two-factor authentication throttlingUnderstand rate controls protecting repeated 2FA-code submissions.
Open guide →GuideUse secure HttpOnly and SameSite cookie defaults
Use secure HttpOnly and SameSite cookie defaultsUnderstand the hardened defaults applied to authentication and session cookies.
Open guide →GuideUnderstand session regeneration improvements
Understand session regeneration improvementsUnderstand improved session-identifier replacement around authentication and security-sensitive state changes.
Open guide →GuideVerify the corrected two-factor assignment flow
Verify the corrected two-factor assignment flowConfirm that 2FA setup and assignment apply to the intended account.
Open guide →GuideUnderstand restricted CSRF exclusions
Understand restricted CSRF exclusionsUnderstand why only explicitly required endpoints may bypass CSRF checks.
Open guide →GuideUnderstand one-way SaaS API-token storage
Understand one-way SaaS API-token storageUnderstand why SaaS API tokens are stored as non-recoverable server-side representations.
Open guide →GuideManage API-token expiry, revocation, rotation and usage metadata
Manage API-token expiry, revocation, rotation and usage metadataUse the complete API-token lifecycle added by the security release.
Open guide →GuideConfigure trusted reverse-proxy handling safely
Configure trusted reverse-proxy handling safelyAllow forwarded connection information only from approved proxy addresses.
Open guide →GuideEnforce production TLS certificate verification
Enforce production TLS certificate verificationUnderstand mandatory certificate and hostname verification for production outbound connections.
Open guide →GuideReview security headers and CSP report-only mode
Review security headers and CSP report-only modeReview response security headers and the initial Content Security Policy reporting mode.
Open guide →GuideUse central security audit logging
Use central security audit loggingUse the consolidated event trail for security-sensitive activity.
Open guide →GuideApply upload and installer web-server protections
Apply upload and installer web-server protectionsProtect uploaded content and installer locations from direct execution or unsafe public access.
Open guide →GuideApply Core migration 342
Apply Core migration 342Apply the core database component required by the hardening release.
Open guide →GuideApply Britixo SaaS migration 040
Apply Britixo SaaS migration 040Apply the SaaS database component required by token and tenant hardening.
Open guide →GuideVerify the updated future-tenant database seed
Verify the updated future-tenant database seedConfirm newly provisioned SaaS tenants receive the hardened baseline.
Open guide →GuideConfirm removal of unnecessary runtime development artefacts
Confirm removal of unnecessary runtime development artefactsVerify that development-only material is absent from the production runtime overlay.
Open guide →GuideRun the post-upgrade security verification checklist
Run the post-upgrade security verification checklistVerify every included hardening item before closing the release change.
Open guide →GuideTroubleshoot a core security hardening deployment
Troubleshoot a core security hardening deploymentDiagnose security-release failures without disabling the new controls.
Open guide →GuideeCommerce & POS Module overview
eCommerce & POS Module overviewStart with the complete code-backed module map.
Open guide →WorkflowReports, audit evidence and security controls
Reports, audit evidence and security controlsThis section explains report filters, exclusions, audit chaining and the module’s principal security controls.
Open guide →WorkflowRead-only API credentials and endpoints
Read-only API credentials and endpointsThis section documents API key creation, authentication, rate limits, list parameters and every supplied GET endpoint.
Open guide →WorkflowSigned webhooks, retries and cron processing
Signed webhooks, retries and cron processingThis section documents endpoint safety checks, event selection, HMAC verification, delivery retries and dead-letter behaviour.
Open guide →