Security Overview
Last updated July 11, 2026. This overview describes the technical and organisational measures Momentum Support Co-operation LTD uses to protect data in Momentum OS. It complements the Privacy Policy at /privacy-policy, the Data Processing Addendum at /dpa, and the GDPR statement at /gdpr. It describes current controls and practices and is not a certification or warranty.
1. Encryption in transit and at rest
Traffic between users and Momentum OS is encrypted using TLS. Data is encrypted at rest by our managed hosting, database, and storage providers using strong industry-standard algorithms.
Uploaded files and identity documents are held in private blob storage that is not publicly listable, and access is brokered through authenticated, time-limited, permission-checked links rather than open URLs.
2. Access controls and RBAC
Access follows least-privilege principles. The platform uses role-based access control so workspace administrators can grant granular page and record permissions, and internal operational access to production systems is limited to authorised personnel who need it for their role.
Personnel with access to customer data are bound by confidentiality obligations, and sensitive actions are constrained by role and, where configured, approval workflows.
3. Multi-tenancy isolation
Momentum OS is a multi-tenant service in which every record is scoped to an organisation. Application queries are organisation-scoped so that one customer's workspace cannot read or write another customer's data, and authorisation is enforced on the server for each request.
Tenant separation is applied consistently across CRM, communications, HR, commerce, and file-storage surfaces.
4. Authentication, MFA, and SSO
The platform supports strong password policies, multi-factor authentication, and step-up verification for sensitive operations. Single sign-on through supported identity providers is available so customers can centralise authentication and enforce their own security policies.
Session handling, credential storage, and integration secrets are managed with security-conscious defaults, and customers are responsible for enforcing MFA and least-privilege roles for their own users.
5. Audit logging and monitoring
Security-relevant and administrative events are recorded in audit logs to support investigation and accountability. Security and audit logs are retained for 12 months.
We monitor the platform for availability and abnormal behaviour and use rate limiting and abuse-prevention controls to protect service integrity.
6. Backups and disaster recovery
Customer data is backed up by our managed database provider, with backups retained for 35 days. Backups support recovery from data loss, corruption, or a regional infrastructure incident.
Recovery procedures are periodically reviewed. Data removed from the live service is also removed from protected backups on the normal backup-expiry cycle.
7. Vulnerability management and testing
We keep platform dependencies current, apply security updates on a risk-prioritised basis, and use automated checks in our build and deployment pipeline. We work toward alignment with recognised frameworks such as ISO 27001 and SOC 2 and can share our current posture with customers under review.
We do not claim any certification as achieved unless a valid attestation is provided directly to a customer. Independent testing, including penetration testing, is arranged on a periodic and risk-driven basis.
8. Incident response and breach notification
We maintain an incident-response process to detect, contain, investigate, and remediate security events. If a personal-data breach affects customer data, we notify affected customers without undue delay so they can meet their own regulatory obligations, and we support notification to regulators and data subjects where required.
Our breach-handling commitments for customer data are set out in the Data Processing Addendum at /dpa and the GDPR statement at /gdpr.
9. Hosting and infrastructure
Momentum OS runs on reputable managed cloud infrastructure with physical and environmental security handled by those providers. The specific providers and their roles are listed in the Subprocessor Notice at /subprocessors.
Infrastructure providers are selected in part for their own security posture and compliance certifications.
10. Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please email leon@momentumos.co.uk with details and steps to reproduce, and give us a reasonable opportunity to investigate and remediate before any public disclosure.
Please do not access, modify, or delete data that is not yours, and avoid privacy violations or service disruption while testing. General security questions can be sent to info@momentumos.co.uk or by phone on +44 1263 808887.