Speakap
Speakap
Service Detail

Security & Compliance — Speakap Frontline Platform

An ISO 27001-aligned information security management system underpinning GDPR obligations, with a role-based access model, encryption in transit, malware scanning on upload, SAML single sign-on and documented disaster recovery — relevant once the app is carrying rotas, payslip notices and incident reports.

Free Advisory

Fibi sources Speakap Security & Compliance at no cost to you. Our advisory is funded by the carrier.

Side-by-Side Comparison

We compare Speakap against 300+ carriers so you know you're getting the best solution for your needs.

Post-Sale Support

Dedicated advisor for the life of your contract — Fibi escalates issues on your behalf so you're never dealing with carrier support alone.

Key Features

Why this matters for a staff app

A frontline communication platform stops being a convenience the moment it carries shift rotas, payslip notifications, absence reasons and incident reports. At that point it is processing employee personal data, and the security posture of the vendor becomes your compliance problem as the employer.

ISO 27001-aligned management system

Speakap operates a formalised Information Security Management System — documented procedures and policies, named owners for systems and assets, regular internal checks and audits, and a risk assessment procedure that directs where controls get strengthened. This is what makes the GDPR position defensible rather than asserted.

Access model built around groups and roles

Users hold a role at organisation level that determines their rights across the network, and a separate role within each group they belong to. Group content is visible only to that group's members, and private messages only to sender and recipient. Administrators are designated rather than implicit — so a store manager does not automatically see head-office material.

Encrypted in transit

Connections to and from the service run over HTTPS with TLS and AES encryption, with the older and weaker SSL protocol disabled and sensitive cookies flagged secure and HTTP-only.

Uploaded files are scanned

Files uploaded by users are automatically scanned for malware on upload and rejected if anything is found, with definitions updated automatically. On a platform where staff share photos and documents from the floor, this is the realistic attack path.

Single sign-on and password handling

SAML 2.0 is supported for single sign-on, so accounts can follow your existing identity provider and joiners and leavers are handled centrally. Passwords are stored as salted BCrypt hashes, changing a password requires the old one, and all active access tokens are revoked on password change.

Input handling and application hardening

User input is validated before processing with specific attention to cross-site scripting, cross-site request forgery and SQL injection. API authentication is based on OAuth 2.0 with short-lived access tokens.

Testing, recovery and incident response

The platform is covered by regular penetration testing and automated security testing, with documented disaster recovery, backup and redundancy arrangements and a defined incident response process.

Frequently Asked Questions

Common questions about Security & Compliance from Speakap.