BI & Data Analytics Technology | Phocas

Our technology is built with world-class data security

At Phocas, we are committed to providing a robust and reliable software application, supported by first class data security and privacy for our customers.

Our goal

A secure end-to-end solution

Conscientious about security, vigilant about monitoring and quick to react

It is critical that our customers have confidence in the security of our application.

To provide a secure end-to-end solution, we continually upgrade our systems by investing in the latest technologies. We work closely with our respected partners, Amazon Web Services (AWS) and CrowdStrike security to follow industry best practice.

While we have enlisted some of the best technology partners in the world to create a secure environment, the responsibility for data security ultimately lies with us;

Compliance and certification

SOC 2 Type 2

We are audited for SOC 2 (System and Organization Controls 2) compliance annually for Security and Availability. Our current SOC 2 Type 2 report is from calendar year 2025.

Established by the American Institute of Certified Public Accountants (AICPA), the examination validates Phocas’ security practices and controls and ensures that Phocas meets the Trust Services principles and criteria for security and availability over an extended period of time.

B Corp certified

To achieve B Corp certification, a company must meet the following criteria:

Phocas earned an overall score of 82.5 in the B Impact Assessment, well above the median score of 50.9.

Data privacy

Customer data is our responsibility, and we’re committed to protecting it from unauthorized access and supporting our customers in meeting their data privacy obligations. We provide information and governance controls to help you make the right decisions for your organization. Additionally, we’ve invested heavily in GDPR, Privacy Shield, and stringent privacy safeguards to keep your data private and under your control.

We publish and regularly update our Privacy Policy which outlines how we collect, use and process data for our own use, and for use by our customers in the Phocas platform.

Additionally, we comply with data privacy laws and regulations in the United Kingdom, European Union, Australia, New Zealand and the United States to ensure customer data is safe and protected.

Our Partners

Through partners, we continually measure current processes, procedures and the security stance against best practice based on our partners’ recommendations. For infrastructure best practice and remediation activities, we work with our partners AWS and CrowdStrike to provide and maintain a compliance baseline. Additionally, we maintain several compliance and monitoring tools that assist in identifying gaps, ensuring we continually maintain compliance.

Infrastructure

Architecture and environment

To provide customers with the greatest degree of reliability, performance and security, we host data in several global locations, including the USA, Canada, UK, EU and Australia.  We are always looking for the next steps in hosting infrastructure, to constantly improve our offering to customers. We maintain an ongoing focus on security, performance and compliance. To achieve this, internal platform specialists actively work with our cloud hosting partners AWS and tools to continually investigate and deploy the latest technology.

Maintenance and monitoring

Rigorous planning and processes have been put in place to enable continuous maintenance and monitoring of our services and infrastructure.

Configuration management

All our servers and infrastructure components are managed through a centralised configuration management system. All changes adhere to our standard change management process and are tracked and stored via source control.

Upgrades to firmware and OS (patching)

All our servers and infrastructure components are upgraded according to the manufacturer and partner (support and security) recommendations. All upgrades are scheduled, automated and monitored.

Deployment of product releases

Our product software upgrades are scheduled weekly. Upgrades are performed out of business hours for each region and have no functional impact on users.

Backups

Under our robust backup plan, essential data stored on the Phocas Cloud (our private network) is automatically backed up daily and stored offsite. Processes are automated via AWS tools and monitored by AWS and our internal teams.

Capacity planning and monitoring

We use the latest autoscaling tools provided by our partners. We automatically monitor the availability, performance and capacity of our end-to-end platform. We meet regularly to proactively identify and rectify potential issues.

Availability

We have a target of 99.9% infrastructure availability and achieve 99.98% (average of Production infrastructure Q1 2026). We maintain a web page that reports on infrastructure availability and service interruptions. All our Phocas customers are hosted on AWS infrastructure that is built with availability, security and redundancy at its core.

Support

Our platform is monitored and supported all day, every day. Our technical teams in our global regions work to a “follow the sun” support model. Our support capability is further enhanced by the AWS enterprise technical support teams.

Security and privacy

We are committed to providing security for all customers, always.

Our infrastructure has been designed with security built in at every stage. Infrastructure designs are reviewed according to the security standards set by AWS, via their best practice ‘Well Architected Review’ process.

Additionally, we partner with CrowdStrike who provides constant monitoring of all our server infrastructure. They identify any irregularities on our servers 24 hours a day, 365 days a year.

Zero Trust

Our security is built on the principle of Zero Trust and this is demonstrated by the following principles and actions;

All servers and infrastructure components are updated regularly to ensure we always follow vendor security recommendations.

Segmentation and separation of data and environments

We host customer data in geographically diverse regions to ensure maximum performance and maintain data sovereignty. Each region is hosted on distinct AWS accounts and networks, then further segregated into production, internal, development and testing environments.

Penetration testing

We annually assess vulnerabilities in our internal and external facing environments with third-party penetration security specialists. All recommendations are prioritized and addressed by our internal multi-disciplinary security team.

Additionally, through AWS and CrowdStrike, we have daily, year-round monitoring and alerting of any irregularities on the perimeters and inside of our hosted environments. Armor provides us with real-time threat response, intrusion detection and prevention, malware protection, file integrity monitoring and vulnerability scanning.

Data security and encryption

All data transferred to and stored within the Phocas Cloud uses industry-recognized encryption methods.

We support AES256, TLS1.3 at a minimum and continually revise these standards as options become available.

Data is encrypted in-flight using HTTPS or SFTP.

AI security and data governance

AI features and capabilities operate under our existing security and data governance controls. Following the same access controls, encryption standards, and operational safeguards that apply across the Phocas platform.

Customer data and public AI models

Customer data processed through AI features is not used to train public or shared foundation models. Where third-party AI providers are used, enterprise configurations are applied that do not permit data retention for model training.

Customer authorization

Structural operational and financial data, including reporting data and underlying transactional records, are not transmitted to external AI services unless the relevant AI feature is enabled and explicit customer authorization has been provided. External processing occurs solely to support the defined functionality of the enabled feature.

Enterprise-level agreements

Where AI functionality requires external processing, Phocas uses enterprise-level agreements with trusted technology providers. Data is transmitted securely and handled in accordance with technical and organizational safeguards.

Phocas application

The Phocas application suite is a variety of multi-tiered-architecture applications, consisting of the following layers:

Firewalls (network and application) and load balancers support and secure this design.

Quality assurance and testing

All our development change processes have quality and security components built in, covering:

Additionally, our development teams ensure ongoing quality is being met, with static code analysis, test coverage and quality metrics. The automated test suite includes UI, unit, functional, integration, e2e, m2e, and regression testing across all stack layers in the application. Manual smoke testing is conducted against all new features. All software development and testing environments are separated from customer production environments for quality assurance.

Development and deployment pipeline

We employ strict processes around all aspects of application development and deployment.

Agile work practices allow us to rapidly address and resolve any identified issues or bugs.

All application design work is planned and managed via cloud-based collaborative design interfaces and tracked via an integrated ticketing system.

All developer work (features, bug fixes, improvements) is planned, managed, and tracked via an integrated ticketing system. All committed code is stored in a source-control repository. Development is performed via a unique branch for each issue, prior to peer review and manual and automated testing. The branch is then merged with other changes for further testing before the deployment process.

Packaged software is automatically created, published and sent via a deployment pipeline, allowing for a reusable and formalized deployment process that updates the development, preproduction and production environments.

Real time application monitoring is configured against development and production environments.

Security

The application is designed and developed with built-in security to prevent Open Web Application Security Project (OWASP) risks including SQL Injection, Cross-Site Scripting (XSS) and Control Functional Level Access.

A dedicated security group actively monitors, assesses and addresses security risks. New risks are identified internally via automated tools and manual testing, and externally via third party auditing and penetration testing.

Within the application itself, there are additional options for customer administrators. This includes password policies and user permission configuration. We provide support for thirdparty authentication, such as LDAP and SAML. All user passwords are encrypted, salted per user and hashed prior to storage.

Phocas AI

Phocas AI has been enabled for customers for all Analytics databases. Phocas AI uses ChatGPT from OpenAI (our Data Processor).

When users 'Ask a question about their data' we share the following with OpenAI:

The user's local date and time.

User questions may be retained by OpenAI for up to 30 days.

We never share the values contained within Dimensions, Streams, Properties and Measures.

We never share any transactional data.

None of the data will be used for any other purpose other than answering the question. It isn’t ever used for training.

Operational practices

All Phocas practices and processes are aligned to the security and protection of customer data. This includes operational and preparedness processes throughout the organization.

Access to customer data

All our staff and contractors are fully vetted prior to employment, bound by non-disclosure agreements, and must follow agreed procedures when dealing with customer data. This is stated and enforced through approved policies for internal use of data (personal and company).

All access to data, including customer data, is strictly controlled on a needs or minimum access basis. Access to customer data can only be approved as a result of an application support request. Access to customer data is authorized and tracked via our internal ticketing systems. All access is logged and auditable.

Change management

We use structured change management processes and tools to ensure all access and changes are logged, approved and kept for audit purposes. This includes all updates to software and operating systems in the product and the platform.

Disaster recovery and incident response

We maintain company-wide business continuity and disaster recovery procedures, to ensure that in case of an incident, any impact on customers is minimal. These procedures rely on stringent backup policies and network redundancy plans, designed to ensure the efficient recovery of services and customer data, if required.

We have the following standards for system recovery:

Customer level data

Server level data

Technology partners

To keep at the forefront of technology and security, we partner with high-quality specialists in technology and security. Our main technical partners are Amazon Web Services (AWS) for support, infrastructure and security, and CrowdStrike for proactive security monitoring, identification and incident response.

We house all multi-tenant platform customers on multiple global Amazon Web Services (AWS) environments.

AWS’ global infrastructure is designed and built to deliver a flexible, reliable, scalable, and secure cloud computing environment with the highest quality global network performance. Every component of the AWS infrastructure is designed and built for redundancy and reliability.

As an AWS partner, we have access to the latest technology advancements and services.

CrowdStrike is a global cybersecurity leader with an advanced cloud-native platform for protecting endpoints, cloud workloads, identities and data.

We partner with CrowdStrike to strengthen and monitor all hosted servers, cloud configurations and services. CrowdStrike provides prevention, detection and response services via its tools and team all day, every day.

It continuously scans for the latest cyberthreats, viruses, malware, phishing scams and mining software, so it can provide proactive end-to-end prevention, detection, and response services to us and our customers.