Cloud Security
Ramsys Central
Security, Architecture & Hosting Overview
1. Platform Overview
Ramsys Central is a cloud-hosted ERP and business management platform designed for multi-site retail/Hospo/Service and operational environments.
The system is delivered via secure cloud infrastructure operated by established technology partners. The platform has been continuously developed and hosted within this environment since 2006, with a focus on reliability, performance, and security.
Access is provided via HTML5-compatible browsers using secure remote application delivery protocols, ensuring accessibility across Windows, macOS, Linux, and mobile devices.
2. Data Ownership & Sovereignty
Customer data ownership is absolute.
- Customers retain full ownership of all data at all times
- Data is never shared between customers
- Data export is available upon request
- No third-party claims or usage rights exist over customer data
Data sovereignty is a core design principle of the platform.
3. Hosting Architecture
Ramsys Central is hosted within a structured cloud environment consisting of three core layers:
- Presentation Layer: HTML5 browser-based access
- Application Layer: Secure Ramsys application services
- Data Layer: Dedicated MySQL 8 database per customer
Key Architecture Principles
- Each customer is provisioned with a dedicated, isolated MySQL database
- No shared database schemas or multi-tenant data structures are used
- Full logical segregation of customer data is enforced at database level
- No direct public access to databases or server infrastructure is permitted
- Application-layer mediation controls all data interaction
Optional dedicated server environments with full RDP access may be provisioned on request.
4. Identity & Access Management
Access control is enforced through structured identity and privilege management:
- Role-Based Access Control (RBAC) across all system modules
- Principle of least privilege enforced by default
- Controlled user lifecycle management (joiner / mover / leaver process)
- Optional IP-based access restrictions for enhanced control
- Optional Multi-Factor Authentication (MFA) for privileged access
- Configurable account lockout policies after repeated failed logins
- All authentication and access events are fully logged and traceable
5. Database Security (MySQL 8)
The platform operates on MySQL 8 with hardened configuration standards.
Authentication & Credentials
- Minimum password length: 8 characters
- Complexity requirements enforced (upper, lower, numeric, symbol)
- Dictionary-based passwords are not permitted
- Root/administrative database access is not granted to customers
- Credentials are encrypted using AES
- Decryption occurs only in volatile memory (RAM)
- Credentials are never stored in plaintext on disk
Access Control
- Database access is restricted to Ramsys application services by default
- External database access requires formal customer authorisation
- Privileges are strictly limited to required operational functions
Transport & Engine Security
- Secure compressed communication protocol used by default
- TLS/SSH encryption available where required
- MySQL 8+ client drivers required for compatibility
Hardening Measures
- Symlink functionality disabled
- LOAD DATA LOCAL INFILE disabled
- Restricted SHOW DATABASES visibility
- Installation and test databases removed from production systems
- Root account obfuscation available on request
- Non-default port mapping available where required
6. Application Security
- All application credentials are encrypted at rest
- No decrypted credentials are written to persistent storage
- Sensitive operations are executed within secure application memory
- Production systems are deployed using compiled, secured binaries
- Access to application services is controlled via authenticated sessions only
7. Network Security
The infrastructure is protected by layered network security controls:
- Segmented firewall architecture between application and database tiers
- Controlled inbound and outbound traffic rules
- Optional IP whitelisting for restricted environments
- TLS encryption enforced for remote sessions
- No direct public exposure of database or internal services
- Infrastructure-level DDoS protection provided by hosting partners
- Intrusion detection and monitoring systems operating at infrastructure level
8. Monitoring & Threat Detection
Continuous monitoring is applied across all hosted environments:
- ConnectWise Automate for infrastructure monitoring
- Liongard for configuration visibility and KPI dashboards
- ID Agent integration for dark web credential exposure monitoring
Monitoring includes:
- System uptime and performance tracking
- Security event detection and alerting
- Configuration drift identification
- Credential compromise monitoring
- Capacity and resource utilisation alerts
All alerts are actively monitored by technical support teams.
9. Audit Logging & Traceability
Comprehensive audit logging is implemented across the platform:
- User authentication and session activity
- Data creation, modification, and deletion events
- Administrative and configuration changes
- Role and privilege modifications
- System and security events
Audit logs are:
- Time-stamped and user-attributed
- Protected against unauthorised modification
- Retained according to configurable policies
10. Encryption Standards
Data in Transit
- Encrypted using modern TLS protocols (TLS 1.2 or higher)
Data at Rest
- AES-256 encryption applied to stored data and backups
- Optional encryption at backup device level
Key Management
- Encryption keys are isolated from application environments
- Keys are not stored in plaintext within application systems
- Access to key material is strictly controlled at infrastructure level
11. Backup & Disaster Recovery
A dual-layer backup strategy ensures resilience and recoverability:
- Local backup via Datto appliance
- Offsite cloud replication for redundancy and disaster recovery
Backup Capabilities
- Image-based system backups using Volume Shadow Copy Service (VSS)
- Frequent scheduling (as low as 5-minute intervals)
- Bare metal recovery support
- Virtual machine conversion (Hyper-V / VMware)
- Cloud-based recovery options
Verification & Integrity
- Automated daily backup boot testing
- Screenshot-based verification of successful recovery
- Ransomware detection within backup datasets
Recovery Objectives
- Recovery Point Objective (RPO): Configurable, down to near-real-time intervals
- Recovery Time Objective (RTO): Dependent on system size and recovery method
Resilience Features
- Inverse Chain Technology enabling instant recovery points
- Instant virtualisation of backup images
- AES-256 encryption for backup data
- Configurable retention policies based on storage capacity
12. Vulnerability & Patch Management
Security maintenance is managed through controlled lifecycle processes:
- Regular operating system and application patching
- Dependency and infrastructure updates
- Vulnerability scanning and assessment cycles
- Controlled deployment and release management
- Rollback capability for critical updates
- Testing environments used prior to production deployment
13. Incident Response
A structured incident response framework is in place:
- Detection via monitoring and alert systems
- Containment of affected systems
- Threat eradication and remediation
- System recovery and restoration
- Post-incident review and reporting
Where appropriate, customers are notified of security incidents affecting their environment.
14. Business Continuity
The platform is designed for high availability and rapid recovery:
- Redundant cloud infrastructure
- Offsite and off-device backup replication
- Rapid restore capability via image-based recovery
- Optional multi-environment deployments for critical workloads
15. Remote Support & Service Access
Secure remote support is delivered via ConnectWise:
- Encrypted remote session access
- Time-controlled and permission-based support connections
- Stronger security model than legacy remote tools
- Customer-controlled activation of support sessions
Remote support access can be enabled for customer internal IT use where required.
16. Compliance & Data Governance
The platform is designed to align with modern security and compliance expectations:
- Full customer data ownership
- Strict per-customer data isolation
- Comprehensive auditability of system actions
- Secure credential storage and encryption standards
- Data export capability on request
- Alignment with GDPR-style principles where applicable
17. Summary
Ramsys Central is engineered as a secure, resilient, and scalable cloud platform with layered protection across identity, application, database, network, and infrastructure domains.
Security is implemented as a multi-layered architecture rather than a single control point, ensuring strong isolation, continuous monitoring, and rapid recovery capabilities across all customer environments.