Skip to main content

How H2CommandCentre is hosted, updated, and secured

H2CommandCentre is hosted in Microsoft Azure data centres in Canada, updated by H2Safety with advance notice, and secured with role-based access.

Written by Phil Wheaton

This article answers the questions your IT and compliance teams ask: where the data lives, how it is protected, who controls access, and how updates land. It is written for administrators.

Where your data lives

H2CommandCentre is hosted in Microsoft Azure, in data centres located in Central Canada. All production data is held within Canada and conforms to Canadian regulatory requirements. Service levels for the hosting layer are covered by Microsoft Azure's service level agreements, and H2Safety works with each client to adhere to agreed data retention schedules.

Callout servers that place phone calls to residents run in remote data centres protected by physical and environmental security under the hosting providers' policies.

How your data is protected

H2Safety operates a documented information security program aligned to the SOC 2 Trust Services Criteria, with a full suite of information security policies and procedures, assigned ownership, and an annual review cycle. The program is SOC 2 attested.

Your data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. The hosting environment follows a defence-in-depth architecture: database and storage services have public network access disabled and are reachable only through private endpoints, network traffic follows a default-deny posture, and public-facing resources sit behind a web application firewall. Arctic Wolf provides 24/7 managed threat detection and monitoring across the environment.

Full system backups run daily and incrementals every four hours, both encrypted and stored geographically separate from production. A geographically separate failover environment is maintained and tested at least annually so service can be recovered against defined targets. Information is classified and handled to a documented standard, retained per an agreed schedule, and securely disposed of when it is no longer required.

Who controls access

  • Accounts: every application account is uniquely assigned to a named individual. User accounts and credentials are stored in a secured database with passwords encrypted.

  • Authentication: access requires an H2CommandCentre account, with multi-factor authentication and single sign-on supported. See Sign in to H2CommandCentre.

  • Authorization: access is restricted by role, per application, on a least-privilege basis. The available roles are Super Admin, Admin, User, and No Access. See Understand roles and permissions.

  • Self-administration: Contact Manager gives your administrators the tools to manage users and their access directly. When an employee leaves, deactivate their credentials and their platform access ends. See Manage user accounts.

  • Mobile: if a device needs a remote wipe, follow the standard process for the device's operating system.

How updates work

H2Safety updates the applications on a continuous improvement basis. Before an update, H2Safety contacts your company's primary contacts to schedule it so business activities are not impacted.

Who owns the data

You do. Exports can be provided on request. If service ends, H2Safety follows an agreed data deletion process and works with you to de-provision user accounts.

Related

Did this answer your question?