Drupal security

A website can be compromised at many levels: the code, the configuration, the platform, and the people who work on it. We build security into each one.

Everyone on our team has a police check, and many of our Australian team members hold baseline security clearance, so federal projects can start without onboarding delays.

Security you can check, at every level

We know the threats differ at each level of the stack, and we put practices in place to reduce the risk as far as is reasonable. Our sites are hardened using best practices, and they're able to pass penetration tests run by third parties.

We also treat your users' data, and your organisation's confidential information, with the care it deserves.

What you get:

  • Vetted people. Police-checked staff, with baseline clearance for federal work.
  • A hardened build. Secure code, protected credentials, and no real user data on developer machines.
  • Ongoing protection. Security alerts monitored and fixes applied under a support and maintenance plan.

Our approach to security

Vet and train the team

Every staff member undergoes a Federal Police check before working on any project. Many of our Australian team members have baseline security clearance for federal government projects. Developers understand their responsibilities for user data privacy and client confidentiality.

Write secure code

Our developers are trained in secure Drupal coding, including how to handle and sanitise data and avoid common mistakes. We harden our websites with best practices and approaches.

Protect access and secrets

We enforce strong passwords and two-factor authentication, and don't share production credentials between developers. Secrets such as API keys stay out of the database and the code repository. We store them as environment variables or in private files, out of reach of both developers and attackers.

Keep real data off developer machines

Our standard practice is to sanitise user data before it leaves the production system, so sensitive or private data doesn't reach developer machines.

Choose secure platforms and keep them patched

We work with platform providers such as Pantheon, Acquia, and GovCMS, which apply security measures at the platform level. Drupal security holes are fixed constantly, so we monitor security alerts and proactively fix sites covered by our support and maintenance plans.

Frequently asked questions

Drupal has a long security track record and a dedicated Security Team that manages vulnerability disclosure and patching. It's the CMS behind the Australian Government's GovCMS. Security still depends on keeping core and contributed modules patched and following secure coding practices for custom development. The platform is a strong foundation, not a guarantee independent of good practice.

Outdated core or module versions, poorly reviewed custom code, misconfigured permissions, and weak monitoring and incident response. Most publicly known Drupal incidents come from sites that hadn't applied available patches, not from undiscovered platform flaws.

GovCMS SaaS applies patches and infrastructure hardening across all sites on the shared platform, which reduces the load on individual agencies. GovCMS PaaS and self-hosted Drupal put more of that responsibility on the agency or its support provider, which makes an active support and maintenance arrangement essential.

Yes. Every staff member undergoes a Federal Police check before starting a project, and many of our Australian team members 

Latest insights

Beer poured from clean pipelines
Article

The Morpht CI pipeline caught a recent vulnerability in Drupal core which led to the problem promptly being fixed.