
MIDAS Information Security Policy
Last Updated: 31st August 2026
This Information Security Policy sets out how we protect the confidentiality, integrity, and availability of the information entrusted to us in the course of providing our MIDAS room booking and resource scheduling software and our associated "cloud-hosted" service.It should be read alongside our Data Processing Agreement, our Data Retention Policy, our Software Privacy Policy, our Sub-Processors & Third Party Services list, and the material published at our dedicated security centre.
1. Scope
This policy applies to:- the MIDAS software, in both its "cloud-hosted" and "self-hosted" editions;
- the infrastructure on which "cloud-hosted" MIDAS systems run;
- the customer data held within "cloud-hosted" MIDAS systems, and the backups of that data;
- our own business systems, records, and the devices used to administer the service;
- all personnel with access to any of the above.
2. Responsibility
- Accountability for information security is assigned directly to a single named Information Security Owner, and is not delegated or diffused. That role holds responsibility for this policy, for security decisions relating to the design, development, and release of MIDAS, for the configuration and administration of our hosting infrastructure, for the triage and resolution of vulnerability reports, for the handling of security incidents and personal data breaches, for the selection and oversight of our sub-processors, and for the publication of our security advisories and audit records.
- The Information Security Owner may be contacted at [email protected]. Guidelines for reporting a security concern or vulnerability to us are published at security.midas.network/reporting.
- Every person with access to the systems or data covered by this policy is responsible for complying with it.
3. The information we hold
- Customer data. The data held within a "cloud-hosted" customer's MIDAS system. This typically comprises the names and contact details of that customer's users and of individuals associated with bookings, together with booking, venue, and resource records. In respect of this data, the customer is the data controller and we are the data processor.
- MIDAS is not designed or intended for the storage of special category data, and in particular is not intended for the storage or handling of patient health information. Please see Is MIDAS HIPAA compliant?. Customers remain responsible for the classes of data they choose to enter into their MIDAS system.
- Business data. Our own customer, licence, subscription, and correspondence records, retained in accordance with our Data Retention Policy. Payment card details are never held by us; online payments are handled by third party payment processors and full card details are neither disclosed to nor stored by us.
- Product and operational data. Our source code, build artifacts, configuration, credentials, and logs.
- Customer data is treated as confidential by default. It is not accessed other than where necessary to provide, support, or secure the service, and is never used for any secondary purpose.
4. Access control
Access is granted on the principle of least privilege, and is limited to what is necessary to operate and support the service.- Administrative access to the servers hosting "cloud-hosted" MIDAS systems is restricted to a single named individual. It is not shared with, or issued to, any other party.
- Such access is permitted only from a defined set of fixed, dedicated IP addresses, enforced at the host firewall. Connections originating from any other address are refused.
- All administrative connections are made over encrypted channels, and are recorded in server access logs.
- Customers have no shell, root, or operating system level access to our hosting infrastructure. Access to a "cloud-hosted" MIDAS system is solely via the supplied web interface or the optional API, as set out in our Cloud Hosted Terms & Conditions.
- Access rights are reviewed whenever there is a change in circumstances, and at minimum as part of the annual review of this policy.
- Credentials are unique to each system, are not reused across systems, are stored securely, are never shared, and are changed on any suspicion of compromise.
5. Security controls available to our customers
MIDAS provides controls allowing customers to enforce their own access policy within their booking system:- individual named user accounts, with granular per-user and per-group permissions;
- two-factor authentication, via an authenticator app or by email, which may be enforced across all accounts or applied on a per-account basis;
- single sign-on via SAML 2.0 identity providers, allowing authentication (and the customer's own multi-factor policy) to be delegated to the customer's own identity provider;
- single sign-on via LDAP / Active Directory for "self-hosted" systems;
- configurable password policy, session timeout, and concurrent session restrictions;
- optional notification to a user whenever their account is accessed from an unfamiliar device;
- an activity log recording user actions, timestamps, originating IP addresses, and optionally location (via the Geolocation add-on);
- a built-in Security Audit tool, allowing a customer's own administrators to review the security configuration of their MIDAS system on demand.
6. Encryption
- All connections to "cloud-hosted" MIDAS systems are made over HTTPS/TLS.
- Customer databases are encrypted at rest.
- Off-site backups are encrypted at rest.
- Administrative access to our servers is over encrypted channels only.
- User passwords within MIDAS are stored using a one-way cryptographic hash, and are not recoverable in plain text.
7. Operational security
- Segregation. Each customer's MIDAS system has its own separate database and files. Although more than one customer's system may reside on the same server, systems are logically separated from one another, and no customer has access to another customer's data.
- Patching. Operating system and control panel patching of the underlying servers is performed by our hosting provider under their fully managed service, and the control panel is maintained on a current supported release. Updates to the MIDAS software itself are issued by us on our published release cycle, with security fixes released as required and recorded in our security changelog.
- Malware protection. Malware detection and scanning software is installed and maintained on our servers. Devices used for administrative access run current, actively maintained endpoint protection and are kept patched.
- Network protection. A host-based firewall is deployed on each server, restricting inbound access to required services and enforcing administrative IP allowlisting. It monitors authentication activity and automatically blocks hosts exhibiting brute-force or otherwise anomalous behaviour. A content delivery and security layer sits in front of all "cloud-hosted" MIDAS systems, providing DDoS mitigation, rate limiting, and web application filtering. Our hosting provider operates further network-level protection and monitoring at the data center perimeter.
- Logging. Server access, error, and authentication logs are retained, together with firewall and login failure records. Within the application, MIDAS maintains an activity log attributing actions to individual user accounts.
- Monitoring. Service availability is monitored automatically on a 24/7 basis, with a public service status page. Our hosting provider additionally monitors the underlying infrastructure 24/7, and may be engaged for support at any time.
8. Secure development
- Development and testing are carried out on infrastructure entirely separate from live customer systems.
- Live customer data is never used for development or testing purposes.
- Changes are tested before release to production.
- Static (SAST) and dynamic (DAST) application security testing forms part of our release process, so that security implications are assessed before deployment rather than after it.
- All changes are recorded in our public product changelog, and security-relevant changes additionally in our security changelog.
- Where a resolved vulnerability warrants customer notification, we publish a security advisory.
9. Security testing and assurance
- Independent external security researchers conduct penetration testing of MIDAS under our published coordinated vulnerability disclosure programme.
- We maintain a dedicated test target at pentest.mid.as, allowing full-depth application testing to be carried out without any risk to live customer data.
- SAST and DAST testing is performed routinely as part of our development and release cycle.
- Testing results and subsequent remediation are published at security.midas.network/audits.
- We do not hold ISO/IEC 27001, SOC 2, or an equivalent certification. The assurance activities described in this section are what we offer in their place.
10. Backup and recovery
- Daily backups are taken of all active "cloud-hosted" customer MIDAS databases.
- Backups are replicated to two geographically separate off-site locations, and are retained there for six months, after which they are automatically deleted.
- Backups are encrypted at rest.
- Restore procedures are tested, and restores validated.
- Our hosting provider takes its own backups of the underlying servers as part of its managed service.
- Customers with an active subscription may export their own data at any time from within MIDAS.
- Backup locations are published on our Sub-Processors & Third Party Services page, and customers may opt out of off-site replication.
11. Physical security
- "Cloud-hosted" MIDAS systems run on managed virtual private servers leased from a third party hosting provider, located within third party colocation data center facilities. Physical and environmental controls at those facilities are the responsibility of the facility operators, and neither we nor our customers have physical access to the servers.
- Our own premises hold no live customer systems. Where equipment at our premises holds customer data, that data is encrypted at rest, the equipment is held within a secured building, and access to it is restricted to the Information Security Owner.
12. Suppliers and sub-processors
- We maintain and publish a current list of all sub-processors involved in delivering our hosted service, together with the purpose for which each is engaged and the location in which it operates.
- Each sub-processor is required to be bound by data protection obligations equivalent to those we owe to our customers, and we remain responsible to our customers for their performance.
- Sub-processors are selected on the basis of their published security posture, the compliance status of the facilities they operate, their contractual data protection commitments, the data center locations they offer, and demonstrated operational reliability over a sustained period.
- Customers are notified in advance of any intended addition or replacement of a sub-processor, and may object, as provided for in our Data Processing Agreement.
- We rely upon published attestations, provider security notices, and ongoing operational experience in order to monitor our sub-processors. We do not conduct independent on-site audits of them, and we do not review the supply chains of our sub-processors' own suppliers.
13. Data protection, retention, and disposal
- Where a "cloud-hosted" MIDAS system contains personal data, the customer is the controller and we are the processor. Our obligations are set out in our Data Processing Agreement.
- Retention periods for customer databases, backups, business records, and correspondence are published in our Data Retention Policy, as are the timescales within which a customer's database is removed from our live servers following termination.
- We are registered with the UK Information Commissioner's Office, registration number ZA131245.
- We maintain published compliance statements covering the UK and EU GDPR, PIPEDA, FERPA, HIPAA, US state privacy laws, the Australian Privacy Act, and accessibility, and review them as those regimes change.
- We will not disclose customer data to any third party except upon the customer's instructions or where we are legally compelled to do so, and where compelled we will notify the customer unless prohibited by law from doing so.
14. Security incidents
- All suspected or actual security incidents, and all suspected or actual personal data breaches, are handled in accordance with our documented Incident Response Plan, a copy of which is available to customers and prospective customers on request.
- Affected customers are notified without undue delay, and in any event within 72 hours of our becoming aware of a personal data breach affecting their data, as provided for in our Data Processing Agreement. Notification is sent to the Primary Contact we hold on record for the customer's MIDAS system, and it is therefore important that customers keep those details up to date.
- Where an incident affects the MIDAS product more broadly, or affects multiple customers, we publish a security advisory. Service availability incidents are communicated via our service status page.
- If you become aware of a suspected security incident affecting MIDAS, please report it to [email protected] immediately.
15. Vulnerability disclosure
- We operate a published coordinated vulnerability disclosure programme, and we welcome reports from security researchers and customers alike. Reporting guidelines, including permitted scope and details of our dedicated test target, are published at security.midas.network/reporting.
- Reports are acknowledged, triaged, and remediated according to severity. Researchers are credited at security.midas.network/credits, unless they would prefer otherwise.
16. Acceptable use
- The systems and data covered by this policy are used only for legitimate business purposes connected with the operation and support of MIDAS.
- Devices used to access those systems must be kept patched, must run current endpoint protection, must use full disk encryption, and must be locked when unattended.
- Customer data must not be copied to removable media, to personal devices, or to any third party service other than those listed as our sub-processors.
- Credentials must never be shared, reused across systems, or transmitted in plain text.
- Devices used to access those systems must connect via a private, encrypted network. Where that connection is wireless, the network must use current WPA2 or WPA3 encryption with a strong, unique passphrase, must not be open or shared with visitors, must have WPS disabled, and must be segregated from any guest or IoT network.
17. Compliance with, and exceptions to, this policy
- Failure to comply with this policy may result in the withdrawal of access and, in the case of personnel, disciplinary action.
- Any exception to this policy must be recorded, together with its justification and any compensating control, and reviewed at the next review of this policy.
18. Review
- This policy is reviewed at least annually, and additionally following any significant security incident, any material change to our service or its infrastructure, any change of sub-processor affecting the hosting of customer data, or any relevant change in law or regulation. The date of the most recent review is shown at the head of this article.
We reserve the right to amend this Information Security Policy at any time without prior notification
← Return to the Knowledge Base