Mensajes

This is the product's own frame. Your conversations appear here once you have an account.

Get started now
Notificaciones

This is the product's own frame. Alerts about your business appear here once you have an account.

Español

Seguridad

The locks, checked before you asked.

A short, honest summary of how the platform is run: where it lives, what guards the door, what watches the perimeter and what is copied so a bad day stays a bad hour. Each part has its own page, linked where it is described.

Get started now
A request passing the perimeter, the door and the seal before it reaches your work

An illustration of the layers a request passes — a drawing, not a screenshot.

The four parts

What is actually in place.

Hosting — where the platform actually runs

FocalShift runs on dedicated cloud servers in the United States, with the database on a separate managed service rather than as a file sitting beside the website. Nothing about the platform runs on a machine under somebody’s desk.

The cloud provider, the database service and every other company that touches your data are named — with what they do and where they process it — in the Data Processing Addendum. We would rather you read that list than take our word for the shape of it.

The same hosting discipline is a product here: if we manage your website and servers, they get the tooling described on the infrastructure pages, not a different standard from our own.

Signing in — the doors into your account

There is more than one way to sign in — a password, a single sign-on, an app session — and every one of those doors enforces the same rules. A second factor, once you switch it on, is required at all of them: there is no quiet side entrance that skips it.

Signing in is required before a member page will answer at all, and it has been since long before this site opened. Your session travels in a cookie a script cannot read, that only crosses an encrypted connection, and that another site cannot borrow. The most privileged actions ask you to prove it is still you, seconds beforehand, not hours.

Requests that change your records are checked against your own session before they are accepted, and that check is enforcing on both production machines rather than merely watching — a difference we care about enough to have proved it under a real member account rather than in a test.

The perimeter — what stands in front

The machines this platform runs on sit behind a firewall at the network edge, so unwanted traffic is refused before it reaches the server rather than by the server. Domains and certificates are issued and renewed automatically, on a timer, with no human remembering to do it.

Every page is served over an encrypted connection; an unencrypted request is redirected to the encrypted one, and your browser is told for a year, across every subdomain, never to try the unencrypted road again. The pages also carry the quiet headers that stop your browser guessing a file’s type, stop the site being framed by somebody else, hold back the address you came from, and switch the camera, the microphone and location off.

What is deliberately not on this page: we do not claim a certification we do not hold, and we do not describe protections on machines we have not measured. The page changes when the measurement does.

Backups — what happens on the bad day

Copies are taken nightly, encrypted before they leave the machine, stored somewhere other than the machine they came from, and expired on a schedule rather than kept forever.

A copy is not counted as a backup until it has been read back out of storage and checked: the returned bytes are fingerprinted against what was sent, the seal is verified, the archive is walked end to end, and a known value is read back out of it. A backup that cannot be read is not a backup, and the system refuses to call it one.

And the restore has been done, not just written down — the platform was rebuilt from the archives alone onto a bare machine, every table accounted for against its manifest, the sign-in gate still armed, and the check values correct at the other end.

Plainly

The short answers, for the person who has to sign off.

  • Every page of this platform is served over an encrypted connection, and browsers are told to refuse an unencrypted one.
  • Your workspace is separated from every other workspace by the platform itself, on the server side — not by a setting anyone can get wrong.
  • Signing in is required before any member page will answer, and the requests that change your records are checked against your own session before they are accepted.
  • Card numbers never reach FocalShift. Payment details go straight to our payment processor, and the platform stores a record of the transaction, not the card.
  • Actions that matter are written to an audit record, so a question about what happened has an answer that is not somebody’s memory.
  • Anything that can destroy or spend is held behind a confirmation an automated agent cannot give itself.

What this page is not

We would rather be short than impressive.

There is no certification badge on this page, because we hold none yet and a badge you have not earned is the first thing a serious buyer checks. Everything above is either running on the platform today or written into a document in the Legal Centre — and when that changes, this page changes with it.

Ask the hard question before you move in.

Join the beta program

Next Up: Connections

Everything the platform can reach on your behalf, listed plainly.

Pregunta a Maven