← Trust & Security Centre

Security & service safeguards

Clear access.
Defined responsibilities.

Security begins with knowing what a service may access, who can approve a change and how an issue is escalated.

Reviewed 10 October 2026Current website facts · service policy review draft

What this website does today

  • Public information only. The guided concierge and available public AI adapter have no connection to customer accounts, service tickets or Microsoft tenants.
  • No account actions. The concierge cannot run commands, change permissions or administer a client system.
  • No submission from the planner. The enquiry brief is generated for local download. There is no website upload or customer-record form.
  • Separate client support. The access hub links to the existing portal. The website does not collect portal credentials or validate its availability.

These boundaries reduce what this website handles. They do not guarantee that a website or connected service is free from risk. The Privacy Notice explains current website data use.

Proposed service security principles

Review draft: these principles are prepared for adoption. They must be checked against COMPUREP’s operating procedures, supplier arrangements and each service agreement before being treated as contractual commitments.

1. Agree access before work begins

Define service scope, authorised contacts, permitted systems and approval boundaries. Grant only the access needed for the agreed task, with stronger verification appropriate to privileged access.

2. Keep responsibility visible

Identify who owns accounts, licences, backups, changes and escalations. Record the handover points where COMPUREP works alongside an internal IT team or another supplier.

3. Protect information throughout the service

Use approved transfer and storage channels, limit access to relevant people, review operators and subprocessors, and agree retention and disposal requirements. Avoid placing credentials or unnecessary personal information in ordinary tickets.

4. Make changes with appropriate approval

Consider business impact, authorisation, maintenance timing, verification and a recovery approach. Access to a system is not blanket permission to change it.

5. Prepare for incidents and recovery

Agree reporting and escalation routes, preserve relevant evidence, determine affected information and follow applicable notification duties. Backup scope and restoration arrangements need to be agreed and tested for the service concerned.

6. Review access when circumstances change

Review permissions during staff changes, contract changes and offboarding. Agree the return or deletion of information subject to legal retention duties, and document the transfer of operational responsibility.

Privacy incidents and notifications

If personal information may be affected, use the Information Officer contact below as well as your agreed incident channel. POPIA requires notification where its security-compromise provisions apply, as soon as reasonably possible in the circumstances. Applicable EU or UK requirements must be assessed separately; they are not interchangeable with POPIA.

Follow the Information Regulator’s current security-compromise guidance and the POPIA Act, sections 21–22. Do not wait for a website response if your existing service agreement specifies an incident escalation channel.

What this centre does not certify

The Trust & Security Centre publishes explanations and policy documents. Its live concierge check reports configuration only. It is not a threat-monitoring dashboard, an uptime guarantee, an audit opinion or a claim of ISO certification or universal POPIA/GDPR compliance.