Platform security

Private by design. Controlled in practice.

Resicoms gives residents, family members and authorised community teams access to the information and actions intended for them. Security is built into accounts, permissions, content delivery and day-to-day administration rather than added as a single technical feature.

01

Identity and access

Protect access at every level.

A community platform should make everyday information easy to reach without making it public. Resicoms verifies account state, separates user roles and limits repeated sign-in attempts.

Residents

Verified individual accounts

Residents sign in with their own password and must have a verified, active account before private community content becomes available.

Resident information is not a public website

Administrators

Separate protected access

Only authorised administrator accounts can enter the management area, with time-based one-time security codes required in addition to a password.

Administration stays separate from resident access

Sign-in

Abuse-resistant entry points

Login and registration attempts are rate limited, while password-reset links expire and repeated reset requests are throttled.

Automated and repeated attempts are constrained

Family

Explicit invited permissions

Each invited family member uses a separate account. Booking and confidential-message permissions can be granted independently and revoked by the resident.

Access follows consent rather than assumption
02

Private information

Keep sensitive details inside the signed-in experience.

Private content is delivered through controlled application routes. The platform avoids treating resident information like ordinary public website content.

Responses

Private pages are not cached

Authenticated application responses carry private, no-store browser caching instructions.

Shared devices retain less private page content

Files

Managed delivery

Private documents and resident media are served only through authenticated, path-restricted routes with file-type checks.

Private files are not exposed as open asset links

Personal actions

Ownership is enforced

Bookings, appointments, messages and notification actions are checked against the signed-in account and its permissions.

A valid login does not grant access to every record

Notifications

Privacy-safe summaries

Alerts are designed to provide useful context without placing confidential detail in notification titles or device-push previews.

Sensitive context remains in the private platform

Operational security

Safeguards continue beyond sign-in.

01

Auditable administration

Important administrator activity is recorded with the responsible account and time, while passwords, tokens and other secrets are excluded from audit detail.

02

Reconfirmation for sensitive actions

High-impact account and access changes require the administrator to confirm their current password again.

03

Controlled releases

Production releases require HTTPS, disabled debug output, environment checks and a verified recovery point before data-changing activation.

03

Clear responsibilities

Agree the complete service before launch.

Application safeguards are only part of a secure service. Commercial and operational details are documented for each customer rather than hidden behind broad claims.

Service scope

Hosting and recovery

Hosting location, backup arrangements, recovery responsibilities and service boundaries are confirmed for the proposed deployment.

Specific commitments replace vague assumptions

Data protection

Roles and retention

Controller and processor responsibilities, retention expectations, authorised contacts and relevant suppliers are agreed with the customer.

Governance reflects the real community service

Support

Incident and support routes

Support contacts, escalation routes, maintenance communication and incident responsibilities are set out before residents are invited.

Teams know who to contact and what happens next

Review the fit

Bring your security and data questions to the first conversation.

Discuss your requirements