Platform and security overview
This section brings together the platform-level administration and security settings that keep your Interact intranet secure and correctly configured. These are tasks for technical administrators, usually done once during setup or when your configuration changes.
Security
- Cross-site scripting (XSS) in Interact — how Interact guards against XSS and what to consider when adding custom content.
- Custom HTTP headers — add security and policy headers to responses.
- TLS and PowerShell — ensure scripts negotiate a supported TLS version.
Addresses and certificates
- Vanity URLs — serve your intranet on your own domain.
- Importing an external certificate — install a certificate for a vanity URL.
Devices and delivery
- Interact Mobile — the mobile app and its requirements.
- Configure Microsoft Intune for Interact — manage the app through Intune.
Note: Several topics here interact with your identity and network configuration. Where a task depends on sign-in or directory setup, see Authentication and SSO.
Certifications and compliance documentation
The pages in this section cover the security settings you configure yourself. For Interact's own security posture — certifications, audit reports, policies and penetration test summaries — see the Interact Trust Centre.
Interact holds ISO/IEC 27001:2022 and SOC 2 Type 2, along with Cyber Essentials Plus and CSA STAR, and supports GDPR, CCPA and the EU-US Data Privacy Framework. The Trust Centre lists the current position for each.
The summary is open to view. Detailed documents — the SOC 2 Type 2 report, the ISO 27001 Statement of Applicability, completed CAIQ and SIG Lite questionnaires, penetration test reports and the subprocessor list — are released on request, so register through the Trust Centre if your security review needs them.
Tip: If you are completing a vendor security assessment, check the Trust Centre before writing a questionnaire from scratch — CAIQ and SIG Lite responses are already prepared.