Security¶
Last reviewed 6 October 2026.
Consoletium holds a company's books, stock, customers and, with the Payroll & HR module, its employees' pay and bank details. This page describes how that data is protected. Your IT team can ask for our threat model and penetration-test summary at security@consoletium.com.
Where your data lives¶
Hosted companies run on servers in Singapore. Each company has its own database and its own database login, which can open only that database, and its own application container. Companies never share tables. Self-hosted customers keep everything on their own servers, and Consoletium has no access unless given it.
In transit and at rest¶
- All traffic is HTTPS with HSTS. Browsers are told not to frame the application, not to load anything from other sites, and to use the camera only for scanning.
- Employee bank account numbers are encrypted in the database under a key held outside it, and are kept out of the audit trail.
- A company's own Anthropic API key, if it sets one, is stored encrypted and never displayed again.
- Backups are encrypted (AES-256) before they leave the server, include attachments as well as the database, are copied to a separate provider and kept for 14 days. A restore is tested every month.
Signing in¶
- Passwords are hashed with bcrypt. The rule is at least 8 characters and nothing else, following NIST SP 800-63B: composition rules produce predictable passwords, so the protection is the lockout rather than complexity.
- 10 wrong attempts in 15 minutes lock the account for 15 minutes; repeated attempts from one address are slowed across accounts.
- A user created or reset by an administrator must choose a new password before doing anything.
- Signing out, or changing a password, ends the session on the server, not just in the browser.
Inside the application¶
- Every request checks the user's role and permission for that kind of record. Customer-portal users see only their own company's records.
- Modules a company has not bought are refused by the server, not just hidden.
- Every change to a record is in the audit trail: who, when, the old value and the new.
- Per-user rate limits and a time limit on every database query stop one user slowing the system for others.
- If a subscription lapses the system becomes read-only. Your data can always be read and exported.
AI features¶
The AI Agent & Insights module sends the AI service summaries only (counts, amounts, document numbers and item titles), never ledgers, customer lists or employee data. A document is sent only when a user asks for it to be read. Use is capped monthly. A company can use its own Anthropic key, in which case its data goes to Anthropic under its own agreement. See AI features.
How we build it¶
Every change runs automated tests, dependency vulnerability audits, static analysis and a secret scan before it can be released. Dependencies are updated weekly. Releases are versioned, and hosted companies are upgraded one at a time with a backup taken first. An independent penetration test is carried out before general availability and every year after.
Personal data¶
Consoletium is a data processor for the personal data its customers store, under a Data Processing Agreement (Singapore and Malaysia PDPA). It is not used for any other purpose. When a customer leaves they receive a full export, and their database and backups are deleted after the retention period in their agreement.
Reporting a vulnerability¶
Email security@consoletium.com with what you found and how to reproduce it. We reply within two working days, keep you informed, and credit you if you wish. Please do not test against other customers' companies or degrade the service.