
An ISO 27001-aligned information security management system underpinning GDPR obligations, with a role-based access model, encryption in transit, malware scanning on upload, SAML single sign-on and documented disaster recovery — relevant once the app is carrying rotas, payslip notices and incident reports.
Fibi sources Speakap Security & Compliance at no cost to you. Our advisory is funded by the carrier.
We compare Speakap against 300+ carriers so you know you're getting the best solution for your needs.
Dedicated advisor for the life of your contract — Fibi escalates issues on your behalf so you're never dealing with carrier support alone.
A frontline communication platform stops being a convenience the moment it carries shift rotas, payslip notifications, absence reasons and incident reports. At that point it is processing employee personal data, and the security posture of the vendor becomes your compliance problem as the employer.
Speakap operates a formalised Information Security Management System — documented procedures and policies, named owners for systems and assets, regular internal checks and audits, and a risk assessment procedure that directs where controls get strengthened. This is what makes the GDPR position defensible rather than asserted.
Users hold a role at organisation level that determines their rights across the network, and a separate role within each group they belong to. Group content is visible only to that group's members, and private messages only to sender and recipient. Administrators are designated rather than implicit — so a store manager does not automatically see head-office material.
Connections to and from the service run over HTTPS with TLS and AES encryption, with the older and weaker SSL protocol disabled and sensitive cookies flagged secure and HTTP-only.
Files uploaded by users are automatically scanned for malware on upload and rejected if anything is found, with definitions updated automatically. On a platform where staff share photos and documents from the floor, this is the realistic attack path.
SAML 2.0 is supported for single sign-on, so accounts can follow your existing identity provider and joiners and leavers are handled centrally. Passwords are stored as salted BCrypt hashes, changing a password requires the old one, and all active access tokens are revoked on password change.
User input is validated before processing with specific attention to cross-site scripting, cross-site request forgery and SQL injection. API authentication is based on OAuth 2.0 with short-lived access tokens.
The platform is covered by regular penetration testing and automated security testing, with documented disaster recovery, backup and redundancy arrangements and a defined incident response process.
Common questions about Security & Compliance from Speakap.
More from Speakap
A communications platform built for staff who do not sit at a desk — retail floors, kitchens, warehouses, cleaning rounds, security posts. Reaches people who have no company email account and no reason to open an intranet, which is where most internal communication quietly fails.
Your own app in the App Store and Google Play under your name and identity, with updates shipped on a fortnightly cycle. A non-branded option running under the Speakap app exists for teams that want to launch without an app-store presence, and custom domain support comes with the branded tier.
Content goes to a group, a timeline or one person, with membership and rights managed per group rather than globally. That matters at scale: a shift change at one site should not push a notification to eight hundred people at the other forty.
User accounts flow from the HR system by XML, CSV, connector or Active Directory import instead of being maintained by hand. In sectors with heavy turnover this is the difference between an accurate staff list and a directory nobody trusts after six months.