Security and Technical

Features and specifications covering platform security, data sovereignty, infrastructure, accessibility, audit capability, and IT requirements.

Security Page

Last updated 13/05/2026

How it works

The Security page (Admin > Account > Security) provides a centralised hub for viewing and managing your portal’s security posture. The page is organised into five sections. Trust, Help and Reports: three information panels at the top of the page linking to the Tribal Habits Trust Centre (ISO 27001:2022 certification and ISMS documentation at security.tribalhabits.com), useful platform resources (Knowledge Base, Change-log, Status Page, API documentation), and directly to the Analytics reports most relevant to security monitoring (Timelines, Notifications, Logins). Posture: a dynamic summary showing how many controls are active across three categories – platform-enforced controls (active on all portals, cannot be disabled), organisation-enabled controls (toggled on by your organisation), and Tribal Habits-managed controls (managed on your behalf). The count updates automatically as controls are toggled. A keyword search allows admins to find specific controls on the page. Access Controls: configurable settings for session timeout, password complexity, account lockout, and MFA (covered separately). Authentication: SSO configuration and related controls (covered in the SSO feature). Brand: displays whether a custom URL domain and custom email domain are active. Users: controls for monitoring Super Admin counts, audit logging, stale user deactivation, and reviewing accounts locked due to failed logins.

Benefit

Gives admins a single place to understand and manage the security configuration of their portal – without needing to know where individual settings live across the platform. The Posture summary provides an at-a-glance view of overall security health, useful for internal governance reviews, IT audits, or satisfying procurement security questionnaires. The direct links to Trust Centre documentation and relevant audit reports mean security evidence is accessible in seconds rather than requiring a support request. For organisations subject to compliance audits or ISO 27001 assessments, the Security page provides a structured, documented view of controls that can be walked through with auditors or IT teams.

Multi-Factor Authentication (MFA)

Last updated 13/05/2026

How it works

Admins can require multi-factor authentication for users logging in with local Tribal Habits credentials. MFA is configured via the Security page (Admin > Account > Security) under Access Controls. Two independent toggles are available – one for administrators and one for non-administrators (learners, creators, assessors) – allowing MFA to be enforced for either or both groups independently. When MFA is enabled for a user type, those users receive an email containing a one-time code upon login, which they must enter to complete the authentication process.

Benefit

Adds a second layer of protection against unauthorised access, particularly important for admin accounts where a compromised password could expose all user data and training records. The ability to enforce MFA for admins only – without impacting the learner login experience – means organisations can apply tighter controls where the risk is highest without creating friction for the broader workforce. For organisations subject to cyber insurance requirements, ISO 27001 audits, or internal IT security policies that mandate MFA, this provides a native platform control that eliminates the need for workarounds.

Deactivate Stale Users

Last updated 13/05/2026

How it works

Admins can configure the platform to automatically deactivate users who have not logged in within a set number of days. The feature is toggled on via the Security page (Admin > Account > Security) under Users. When enabled, admins set a duration in days (minimum 30) and save. The platform runs periodic checks and deactivates any user – including admins – who has not logged in within the configured period. Each time a check runs, an email is sent to the primary admin email address listing the users deactivated. The duration can be adjusted at any time via the Manage option. The feature can be disabled by toggling it off.

Benefit

Reduces the security risk of dormant accounts remaining active indefinitely – a common finding in IT security audits and a requirement in many cyber insurance policies. Particularly useful for organisations with high staff turnover, contractors, or seasonal workers where offboarding processes are not always reliable. Automatically deactivating stale accounts ensures that former employees or lapsed users cannot access the portal using old credentials, without requiring admins to manually monitor and clean up inactive accounts. The primary admin notification provides an ongoing record of deactivations for audit purposes.

Hosting and Infrastructure

Last updated 13/05/2026

How it works

Tribal Habits is hosted entirely on Amazon Web Services (AWS) in Sydney, Australia. All customer data — including the database, files, assets, and code — is stored within Australia and does not leave Australian jurisdiction. The platform runs on AWS Elastic Beanstalk across multiple instances and availability zones, with load balancers and auto-scaling rules providing failover redundancy. Platform uptime is monitored and publicly visible at status.tribalhabits.com. AWS infrastructure includes built-in DDOS protection, customised firewalls, AI-driven intrusion protection, and automated vulnerability scanning. AWS is used for all components of the platform, including the Sage AI features, which run via Amazon Bedrock in Sydney.

Benefit

Australian data residency is a meaningful requirement for many Australian and New Zealand organisations — particularly those in government, healthcare, education, and financial services where data sovereignty obligations apply. Organisations can confirm that no learner data, training content, or personal information is processed or stored offshore. The public uptime status page gives IT teams transparent visibility of platform availability without needing to contact support.

Data Security and Encryption

Last updated 13/05/2026

How it works

Tribal Habits is ISO 27001:2022 certified for information security management. All data stored at rest is encrypted using AES-256. All data in transit between users and the platform is encrypted via TLS with a SHA2 certificate and a 2048-bit key. Security is continuously monitored 24/7 via AWS Security Hub, AWS GuardDuty (real-time intrusion alerts), and AWS Inspector (automated vulnerability reporting), supplemented by the third-party compliance platform SecureFrame. Annual independent vulnerability and penetration testing is conducted by external third parties. All third-party partners integrated with the platform must hold ISO 27001 or SOC 2 Type 2 certification. Full security policies and documentation are available at the Tribal Habits Security Portal at security.tribalhabits.com.

Benefit

ISO 27001:2022 certification provides formal, independently audited assurance that Tribal Habits operates a mature information security management system — going well beyond a self-declared security posture. For organisations in regulated industries or those conducting vendor security assessments, this certification significantly simplifies the procurement and due diligence process. The public Security Portal makes it straightforward for IT and security teams to review policies without requiring bespoke requests.

Platform Availability and Browser Support

Last updated 13/05/2026

How it works

Tribal Habits is a browser-based application requiring no downloads, plugins, or installations. It supports the latest stable versions of Microsoft Edge, Mozilla Firefox, Google Chrome, Apple Safari, iOS Safari, and Android Chrome — generally the current and two prior versions of each. No Adobe Flash or other browser plugins are required. The platform is fully responsive and supports desktop, tablet (including iPad), and mobile devices. Mobile is supported for learner-facing content exploration; content creation and admin functions are optimised for desktop but accessible on tablet. Users can add a bookmark shortcut to their mobile home screen for app-like access. Tribal Habits is compatible with thin-client and remote desktop environments.

Benefit

Zero IT deployment overhead — no software to install, approve, or maintain on end-user devices. Any device with a modern browser and internet access can use the platform, which is particularly important for organisations with distributed workforces, contractors, casual staff, or remote workers who may not have company-managed devices. Thin-client compatibility means it works in call centre, warehouse, and retail environments where traditional software deployment is not feasible.

Mobile Responsiveness

Last updated 13/05/2026

How it works

Tribal Habits is fully responsive and accessible on mobile devices via any modern mobile browser — no app download required. All learner-facing content, including topic exploration, event registration, and the learner dashboard, is optimised for small screens. Topics are mobile-responsive by default — no additional formatting is required from creators. Learners can add a home screen shortcut to their mobile device by bookmarking the portal URL, creating an app-like launch experience. Tablet devices (including iPads) support all aspects of the platform — learner exploration, content creation, and admin functions — though desktop is recommended for complex authoring and admin tasks. Mobile devices support learner exploration only — content creation and platform administration are accessible but not optimised for small screens. Portrait and landscape orientations are both supported, though landscape is recommended on mobile for the best experience.

Benefit

Allows learners to complete training wherever they are — on the floor, in the field, between shifts, or commuting — without needing a desktop or a company-managed device. Particularly valuable for organisations with frontline, distributed, or deskless workforces such as hospitality, retail, logistics, and early learning, where staff are unlikely to complete training at a desk. The home screen shortcut removes the friction of navigating to a URL, making the platform feel like a native app without the overhead of app store distribution or IT deployment.

Accessibility (WCAG 2.2 Level AA)

Last updated 20/07/2026

How it works

Tribal Habits targets WCAG 2.2 Level AA compliance for the learner-facing experience — including the learner homepage and all topic exploration. The platform is independently audited every 12-24 months against WCAG 2.2 Level A and Level AA criteria. The most recent audit was completed in November 2025 by me2 Accessibility. WCAG compliance covers screen reader support, keyboard navigation, colour contrast (minimum 4.5:1 for standard text), captions and transcripts for Narration and Video elements, and alt text fields for images. Creator and admin interfaces are not audited for WCAG compliance but meet many accessibility requirements in practice. Content creators are responsible for ensuring their own authored content meets accessibility standards — the platform provides the tools (alt text, captions, transcripts) but cannot enforce content quality.

Benefit

Enables organisations with accessibility obligations — under the Disability Discrimination Act, government procurement requirements, or their own inclusion policies — to use Tribal Habits with confidence. The independent audit provides documented evidence of accessibility standards rather than a self-declared claim. Organisations can also demonstrate to learners with disability that the platform supports assistive technologies including screen readers and keyboard-only navigation.

Audit Trail and Timelines

Last updated 13/05/2026

How it works

The Timelines report in the Analytics area provides a comprehensive, searchable audit log of all significant events in the portal. Logged events include: topic and pathway creation, updates, version publishing, and deletion; user creation, profile changes, deactivation, and deletion; enrolment creation, completion, and deletion; admin access changes; certificate views; and more. Each event is timestamped and records the actor (the admin or user who performed the action). The log is filterable by knowledge, person, event type, and date range, and is exportable to CSV. Logs are retained and accessible to admins at any time.

Benefit

Provides the audit evidence required for ISO 27001, compliance audits, and internal governance reviews — showing exactly who changed what, when, and who completed which training. For organisations subject to regulatory oversight, the Timelines report can be used to demonstrate that training records are accurate and tamper-evident. For IT security purposes, it provides visibility of admin access events and data changes without requiring a separate audit logging system.

IT Requirements and Safe Listing

Last updated 13/05/2026

How it works

Tribal Habits has minimal IT requirements. No software installations, plugins, or firewall rule changes are required for most organisations. SAML 2.0 SSO is supported for organisations using Azure AD, Okta, ADFS, or Salesforce. The platform is compatible with thin-client and remote desktop environments.

Benefit

IT teams can assess and deploy Tribal Habits quickly with minimal configuration. The lack of any software installation requirement means there is no endpoint management overhead and no approval process for device-level deployment. For organisations with managed devices or strict firewall policies, the safe-list requirements are straightforward and well-documented, enabling rapid IT sign-off.

Table of Contents