Skip to content

Configuration

The SCF Controls Platform is a fully-managed SaaS application. Configuration is handled through the platform’s web interface rather than environment files or server settings.

Organisation administrators can configure:

SettingDescriptionAccess
Organisation NameDisplay name for your organisationAdmin only
Primary FrameworkDefault compliance framework for dashboard metricsAdmin only
User RolesAssign roles to team membersAdmin only

Individual users can configure:

SettingDescription
Notification PreferencesEmail notification settings
Display PreferencesUI preferences (if available)

The platform uses Google Sign-In for secure authentication. No configuration is required on your part.

Account TypeExampleNotes
Google Workspaceyou@company.comRecommended for organisations
Personal Gmailyou@gmail.comWorks for individuals and small teams
Google Cloud Identityyou@domain.comFor organisations without full Workspace
  1. User clicks “Sign in with Google”
  2. Google authenticates the user
  3. Platform receives user identity (email, name, profile picture)
  4. User is granted access based on their organisation membership

The platform sends email notifications for:

Notification TypeTrigger
User InvitationsWhen invited to join an organisation
Task AssignmentWhen assigned to a control or task
Due RemindersBefore task due dates
Overdue AlertsWhen tasks pass their due date
@MentionsWhen mentioned in comments

  • All data is stored securely in the cloud
  • Data is encrypted at rest and in transit
  • Regular automated backups are performed
  • Multi-region redundancy for high availability
  • Active data is retained as long as your subscription is active
  • Backups are retained according to our data retention policy
  • You can export your data at any time via the backup feature

FeatureDescription
Google OAuthSecure authentication via Google
Role-Based AccessAdmin, Editor, Viewer roles (enforcement coming soon)
Organisation IsolationEach organisation’s data is completely separate
  • HTTPS Only — All connections are encrypted
  • OAuth 2.0 — Industry-standard authentication
  • Session Management — Automatic session timeout for security
  • Audit Logging — All actions are logged for compliance

The platform currently supports:

IntegrationPurpose
Google Sign-InUser authentication
Email (Resend)Notification delivery

Additional integrations are planned for future releases:

  • SIEM/SOAR integration
  • Ticketing system integration (Jira, ServiceNow)
  • Single Sign-On (SSO) providers
  • API access for automation

Access via the Database button in the header:

FeatureDescription
Download BackupExport all your data as a JSON file
Restore from BackupUpload a previous backup to restore data

Backups include:

  • All scoped controls and their status
  • Evidence tracking configurations
  • Users and organisation settings
  • Assignments, comments, and tasks
  • Notification history
  • SCF catalog data (this is reference data provided by the platform)
  • System configuration (managed by the platform)

The platform version is displayed:

  • In the footer of each page
  • In the Database Health & Statistics popup
ComponentDescription
Platform VersionApplication version number
API VersionBackend API version
Catalog VersionSCF Controls Catalog version

ResourcePurpose
This DocumentationSelf-service help and guides
In-App SupportContact support from within the platform
Email Supportsupport@scfcontrolsplatform.com

When reporting issues, include:

  • Browser type and version
  • Steps to reproduce the problem
  • Any error messages shown
  • Screenshots if applicable