Ramsys Central

Security, Architecture & Hosting Overview



1. Platform Overview

Ramsys Central is a cloud-hosted ERP and business management platform designed for multi-site retail/Hospo/Service and operational environments.

The system is delivered via secure cloud infrastructure operated by established technology partners. The platform has been continuously developed and hosted within this environment since 2006, with a focus on reliability, performance, and security.

Access is provided via HTML5-compatible browsers using secure remote application delivery protocols, ensuring accessibility across Windows, macOS, Linux, and mobile devices.


2. Data Ownership & Sovereignty

Customer data ownership is absolute.

  • Customers retain full ownership of all data at all times
  • Data is never shared between customers
  • Data export is available upon request
  • No third-party claims or usage rights exist over customer data

Data sovereignty is a core design principle of the platform.


3. Hosting Architecture

Ramsys Central is hosted within a structured cloud environment consisting of three core layers:

  • Presentation Layer: HTML5 browser-based access
  • Application Layer: Secure Ramsys application services
  • Data Layer: Dedicated MySQL 8 database per customer

Key Architecture Principles

  • Each customer is provisioned with a dedicated, isolated MySQL database
  • No shared database schemas or multi-tenant data structures are used
  • Full logical segregation of customer data is enforced at database level
  • No direct public access to databases or server infrastructure is permitted
  • Application-layer mediation controls all data interaction

Optional dedicated server environments with full RDP access may be provisioned on request.


4. Identity & Access Management

Access control is enforced through structured identity and privilege management:

  • Role-Based Access Control (RBAC) across all system modules
  • Principle of least privilege enforced by default
  • Controlled user lifecycle management (joiner / mover / leaver process)
  • Optional IP-based access restrictions for enhanced control
  • Optional Multi-Factor Authentication (MFA) for privileged access
  • Configurable account lockout policies after repeated failed logins
  • All authentication and access events are fully logged and traceable

5. Database Security (MySQL 8)

The platform operates on MySQL 8 with hardened configuration standards.

Authentication & Credentials

  • Minimum password length: 8 characters
  • Complexity requirements enforced (upper, lower, numeric, symbol)
  • Dictionary-based passwords are not permitted
  • Root/administrative database access is not granted to customers
  • Credentials are encrypted using AES
  • Decryption occurs only in volatile memory (RAM)
  • Credentials are never stored in plaintext on disk

Access Control

  • Database access is restricted to Ramsys application services by default
  • External database access requires formal customer authorisation
  • Privileges are strictly limited to required operational functions

Transport & Engine Security

  • Secure compressed communication protocol used by default
  • TLS/SSH encryption available where required
  • MySQL 8+ client drivers required for compatibility

Hardening Measures

  • Symlink functionality disabled
  • LOAD DATA LOCAL INFILE disabled
  • Restricted SHOW DATABASES visibility
  • Installation and test databases removed from production systems
  • Root account obfuscation available on request
  • Non-default port mapping available where required

6. Application Security

  • All application credentials are encrypted at rest
  • No decrypted credentials are written to persistent storage
  • Sensitive operations are executed within secure application memory
  • Production systems are deployed using compiled, secured binaries
  • Access to application services is controlled via authenticated sessions only

7. Network Security

The infrastructure is protected by layered network security controls:

  • Segmented firewall architecture between application and database tiers
  • Controlled inbound and outbound traffic rules
  • Optional IP whitelisting for restricted environments
  • TLS encryption enforced for remote sessions
  • No direct public exposure of database or internal services
  • Infrastructure-level DDoS protection provided by hosting partners
  • Intrusion detection and monitoring systems operating at infrastructure level

8. Monitoring & Threat Detection

Continuous monitoring is applied across all hosted environments:

  • ConnectWise Automate for infrastructure monitoring
  • Liongard for configuration visibility and KPI dashboards
  • ID Agent integration for dark web credential exposure monitoring

Monitoring includes:

  • System uptime and performance tracking
  • Security event detection and alerting
  • Configuration drift identification
  • Credential compromise monitoring
  • Capacity and resource utilisation alerts

All alerts are actively monitored by technical support teams.


9. Audit Logging & Traceability

Comprehensive audit logging is implemented across the platform:

  • User authentication and session activity
  • Data creation, modification, and deletion events
  • Administrative and configuration changes
  • Role and privilege modifications
  • System and security events

Audit logs are:

  • Time-stamped and user-attributed
  • Protected against unauthorised modification
  • Retained according to configurable policies

10. Encryption Standards

Data in Transit

  • Encrypted using modern TLS protocols (TLS 1.2 or higher)

Data at Rest

  • AES-256 encryption applied to stored data and backups
  • Optional encryption at backup device level

Key Management

  • Encryption keys are isolated from application environments
  • Keys are not stored in plaintext within application systems
  • Access to key material is strictly controlled at infrastructure level

11. Backup & Disaster Recovery

A dual-layer backup strategy ensures resilience and recoverability:

  • Local backup via Datto appliance
  • Offsite cloud replication for redundancy and disaster recovery

Backup Capabilities

  • Image-based system backups using Volume Shadow Copy Service (VSS)
  • Frequent scheduling (as low as 5-minute intervals)
  • Bare metal recovery support
  • Virtual machine conversion (Hyper-V / VMware)
  • Cloud-based recovery options

Verification & Integrity

  • Automated daily backup boot testing
  • Screenshot-based verification of successful recovery
  • Ransomware detection within backup datasets

Recovery Objectives

  • Recovery Point Objective (RPO): Configurable, down to near-real-time intervals
  • Recovery Time Objective (RTO): Dependent on system size and recovery method

Resilience Features

  • Inverse Chain Technology enabling instant recovery points
  • Instant virtualisation of backup images
  • AES-256 encryption for backup data
  • Configurable retention policies based on storage capacity

12. Vulnerability & Patch Management

Security maintenance is managed through controlled lifecycle processes:

  • Regular operating system and application patching
  • Dependency and infrastructure updates
  • Vulnerability scanning and assessment cycles
  • Controlled deployment and release management
  • Rollback capability for critical updates
  • Testing environments used prior to production deployment

13. Incident Response

A structured incident response framework is in place:

  1. Detection via monitoring and alert systems
  2. Containment of affected systems
  3. Threat eradication and remediation
  4. System recovery and restoration
  5. Post-incident review and reporting

Where appropriate, customers are notified of security incidents affecting their environment.


14. Business Continuity

The platform is designed for high availability and rapid recovery:

  • Redundant cloud infrastructure
  • Offsite and off-device backup replication
  • Rapid restore capability via image-based recovery
  • Optional multi-environment deployments for critical workloads

15. Remote Support & Service Access

Secure remote support is delivered via ConnectWise:

  • Encrypted remote session access
  • Time-controlled and permission-based support connections
  • Stronger security model than legacy remote tools
  • Customer-controlled activation of support sessions

Remote support access can be enabled for customer internal IT use where required.


16. Compliance & Data Governance

The platform is designed to align with modern security and compliance expectations:

  • Full customer data ownership
  • Strict per-customer data isolation
  • Comprehensive auditability of system actions
  • Secure credential storage and encryption standards
  • Data export capability on request
  • Alignment with GDPR-style principles where applicable

17. Summary

Ramsys Central is engineered as a secure, resilient, and scalable cloud platform with layered protection across identity, application, database, network, and infrastructure domains.

Security is implemented as a multi-layered architecture rather than a single control point, ensuring strong isolation, continuous monitoring, and rapid recovery capabilities across all customer environments.