Security
Enterprise-grade security,
built into every layer.
Your workforce data is sensitive. We treat it that way — with encryption at rest and in transit, strict access controls, and compliance frameworks trusted by regulated industries.
How We Protect Your Data
Security at every layer
TheDeskMonitor is designed from the ground up with a defence-in-depth approach. Every component — from the desktop agent to the cloud API — follows security best practices.
Data Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. Database volumes use full-disk encryption. Encryption keys are rotated on a regular schedule and managed through a dedicated key management service.
Two-Factor Authentication
Protect every account with TOTP-based two-factor authentication. Admins can enforce 2FA organisation-wide via the security settings dashboard. OTP codes are generated using industry-standard SHA-256 HMAC algorithms.
GDPR Compliance
TheDeskMonitor is fully GDPR compliant. We provide data subject access requests (DSAR), right-to-erasure workflows, consent management, and a published Data Processing Agreement (DPA). Our DPO is available via the Contact page.
SOC 2 Readiness
Our infrastructure and processes are aligned with SOC 2 Type II requirements across Security, Availability, and Confidentiality trust service criteria. Formal audit certification is in progress with a target completion date in Q3 2026.
Data Retention Policies
Configurable data retention ensures that screenshots, activity logs, and personal data are automatically purged after the retention window expires. Data retention periods vary by subscription plan. Your administrator can view the applicable retention period in account settings.
IP Whitelisting
Restrict dashboard access to approved IP addresses or CIDR ranges. Ideal for organisations that require access from known office networks only. Whitelist rules are enforced at the application layer before any data is served.
Role-Based Access Control
Granular RBAC ensures that users only see what they need. Five distinct roles — Owner, Admin, Manager, Employee, and Viewer — each with carefully scoped permissions. Roles are pre-configured with carefully considered permissions per level.
Audit Logging
Every administrative action — login, settings change, data export, user invitation, role change — is recorded in an immutable audit log with timestamp, actor, IP address, and action detail. Logs are retained for a minimum of 12 months.
Secure Infrastructure
TheDeskMonitor runs on hardened Linux containers deployed to ISO 27001-certified data centres. Security headers (HSTS, CSP, X-Frame-Options) are enforced on every response. Rate limiting protects against brute-force and DDoS attempts.
Our Commitment
Security is not a feature.
It is the foundation.
We do not bolt security on as an afterthought. Every line of code, every deployment pipeline, and every operational process is designed with security as a first-class requirement.
Secure Development
All code undergoes peer review. Dependencies are scanned for known vulnerabilities on every build. We follow OWASP Top 10 guidelines.
Incident Response
We maintain a documented incident response plan with defined escalation paths, notification timelines, and post-incident review procedures.
Employee Security
All team members undergo background checks. Access to production systems requires hardware-based MFA and is logged.
Penetration Testing
Third-party penetration tests are conducted annually. Critical and high findings are remediated within 72 hours of disclosure.
Responsible Disclosure
Found a security vulnerability? We appreciate responsible disclosure and will work with you to resolve any issues promptly. Please report security concerns to our dedicated security team.
[email protected]Your data deserves better protection
Start free with 3 seats. Enterprise security on every plan.