ISO 27001 compliant
Information security managed to a certified-grade standard across people, process and technology.
Formation CRM is designed for schemes that manage high-value, high-sensitivity records. Security, privacy and data governance are core to how we design, host and support the platform.
Schemes handle some of the most sensitive personal and financial information in the country. Formation CRM is engineered for secure handling of personally identifiable information at every layer, from how we develop and host the platform to how your operators access it every day.
Information security managed to a certified-grade standard across people, process and technology.
Privacy-first handling of worker and employer records, with secure handling of personally identifiable information.
MFA for back office and portals using phone authenticator apps or SMS, with optional bypass for trusted addresses.
SSO including integration with Active Directory Federation Services (ADFS) for identity and authentication.
Fully-managed, secure cloud hosting with hardened, monitored infrastructure maintained by our team.
Deploy in our managed AWS environment or a dedicated standalone environment in AWS or Microsoft Azure.
Structured, validated and reconciled migration so sensitive data is handled correctly from day one.
Comprehensive audit trail of changes and access across records, returns, claims and correspondence.
Granular, role-based access and row-level permissions so people see only what they should.
Protect accounts from unauthorised logins and give every user exactly the access they need, no more, no less.
We recommend requiring MFA for both the Company and Member portals.
MFA available for all portals.
Unique one-time codes complete each sign-in.
Host in our fully-managed AWS cloud, or in a dedicated standalone environment in AWS or Microsoft Azure. Either way, infrastructure is hardened, monitored and maintained to ISO 27001-aligned controls, with secure mechanisms for connecting your chosen IT systems.
ISO 27001-compliant information security underpins how we develop, deploy and support Formation CRM. A comprehensive audit history records changes and access across the platform, and migration is governed end-to-end so sensitive data is protected from day one.
Formation CRM integrates with the systems your scheme relies on, using simple, powerful and secure mechanisms, so data moves safely between platforms.
We're happy to walk your risk, security and governance teams through how Formation CRM protects sensitive scheme data.