Security you can check, at every level
We know the threats differ at each level of the stack, and we put practices in place to reduce the risk as far as is reasonable. Our sites are hardened using best practices, and they're able to pass penetration tests run by third parties.
We also treat your users' data, and your organisation's confidential information, with the care it deserves.
What you get:
- Vetted people. Police-checked staff, with baseline clearance for federal work.
- A hardened build. Secure code, protected credentials, and no real user data on developer machines.
- Ongoing protection. Security alerts monitored and fixes applied under a support and maintenance plan.
Our approach to security
Vet and train the team
Every staff member undergoes a Federal Police check before working on any project. Many of our Australian team members have baseline security clearance for federal government projects. Developers understand their responsibilities for user data privacy and client confidentiality.
Write secure code
Our developers are trained in secure Drupal coding, including how to handle and sanitise data and avoid common mistakes. We harden our websites with best practices and approaches.
Protect access and secrets
We enforce strong passwords and two-factor authentication, and don't share production credentials between developers. Secrets such as API keys stay out of the database and the code repository. We store them as environment variables or in private files, out of reach of both developers and attackers.
Keep real data off developer machines
Our standard practice is to sanitise user data before it leaves the production system, so sensitive or private data doesn't reach developer machines.
Choose secure platforms and keep them patched
We work with platform providers such as Pantheon, Acquia, and GovCMS, which apply security measures at the platform level. Drupal security holes are fixed constantly, so we monitor security alerts and proactively fix sites covered by our support and maintenance plans.
Frequently asked questions
Drupal has a long security track record and a dedicated Security Team that manages vulnerability disclosure and patching. It's the CMS behind the Australian Government's GovCMS. Security still depends on keeping core and contributed modules patched and following secure coding practices for custom development. The platform is a strong foundation, not a guarantee independent of good practice.
Outdated core or module versions, poorly reviewed custom code, misconfigured permissions, and weak monitoring and incident response. Most publicly known Drupal incidents come from sites that hadn't applied available patches, not from undiscovered platform flaws.
GovCMS SaaS applies patches and infrastructure hardening across all sites on the shared platform, which reduces the load on individual agencies. GovCMS PaaS and self-hosted Drupal put more of that responsibility on the agency or its support provider, which makes an active support and maintenance arrangement essential.
Yes. Every staff member undergoes a Federal Police check before starting a project, and many of our Australian team members
Latest insights