SCICON SYSTEMS Talk to us
Security & architecture

How it is built, and what you are being asked to trust.

Most vendors answer a security question with a certificate. The more useful answer is architectural: what can we technically see, what can we technically do, and where have we deliberately removed ourselves from the equation.

Principle 01

Zero-knowledge where it matters

With PushItPro, content is encrypted before it reaches us. We hold ciphertext we cannot decrypt. That is not a policy commitment that could change with an owner or a jurisdiction — it is a property of the design.

Principle 02

Least data, not most data

Volarian shares documents view-only rather than distributing copies. FlashItSync holds files in object storage with only lightweight metadata alongside. Nothing collects more than the job requires.

Principle 03

Least privilege, and least dependency

Where a product reads from a system you already run — Entra ID, a vendor feed, an object store — it asks for the narrowest access that does the job, and it degrades rather than breaks when that access is withdrawn.

Principle 04

Small attack surface by construction

Nothing in the portfolio installs an agent fleet on your network. Fewer moving parts means fewer things to patch, fewer things to misconfigure, and a deployment an SME can actually reason about.

The stack

What we run on, and why

Cloudflare — edge, Workers, R2Clerk — identity and authenticationNeon — serverless Postgres

A modern serverless stack means a small team can run production infrastructure with real isolation and real resilience, without a data-centre bill to pass on. Authentication is delegated to a specialist rather than hand-rolled, which is the right call for a company this size and an unusual thing for a vendor to admit.

Integrations

What we connect to

Microsoft Entra IDMicrosoft GraphCloudflare R2[Vulnerability data sources — confirm]

Integrations are chosen because SMEs and their providers already run these platforms, not because the logo looks good on a slide. Where a product integrates, it does so natively rather than through a generic connector layer. Confirm this list against what ships today before publishing — an overclaimed integration is the fastest way to lose a technical buyer.

Question a buyer will askOur answer
Can your staff read our data?For PushItPro and Volarian, no — the architecture prevents it. For the other products, access is role-restricted and logged; ask us for the specific answer per product.
Where is our data held?[Confirm and state the region explicitly — Cloudflare supports jurisdictional restriction, and buyers in Scotland and the public sector will ask.]
Do you hold Cyber Essentials?[State the position honestly — held, in progress with a date, or planned. Do not imply certification you do not have.]
Who are your sub-processors?Cloudflare, Clerk and Neon, plus the operational tools listed in our privacy statement. The list is published and we give notice before it changes.
What happens if we leave?Export paths out of every product. Per-product pricing means leaving one does not mean leaving all.
What happens if you are acquired or fail?[Answer this before you are asked. For a small vendor it is the single most common objection, and a source-escrow or data-export commitment defuses it.]