Executive Summary – Private Members’ Online Forum

For IT and Information Security Review

1.0 Overview

Front Forum is a private, invitation-only online platform designed to facilitate professional discussion and knowledge sharing between approved members. It is intended solely for professional discussion and peer engagement.

Access permissions are role-restricted and administratively controlled by Front Forum. The platform is not publicly accessible; it is not a public social media platform and does not permit advertising, recruitment activity or open commercial promotion by members. It does not access any internal corporate systems or infrastructure.

Front Forum does not require, request, or encourage members to share confidential, proprietary, or employer-owned information. Members are responsible for ensuring that their participation complies with their employer’s internal policies.

Supplier access is subject to the following controls:

  • Access is limited strictly to the Supplier Directory profile submission area;
  • Suppliers do not have access to member discussions, messaging functions, or wider Forum content;
  • Suppliers cannot view member-only discussions or download member data;
  • Suppliers are not permitted to initiate contact with members through the platform.

Front Forum operates in accordance with UK GDPR and the Data Protection Act 2018. Details of personal data processing, lawful basis, and data retention are set out in the Forum’s Privacy Notice, available on the website.

The platform is designed as a restricted-access environment with controlled user permissions and moderated content publication.

Front Forum is a private, invitation-only online platform designed to facilitate professional discussion and knowledge sharing between approved members. It is intended solely for professional discussion and peer engagement.

Access permissions are role-restricted and administratively controlled by Front Forum. The platform is not publicly accessible; it is not a public social media platform and does not permit advertising, recruitment activity or open commercial promotion by members. It does not access any internal corporate systems or infrastructure.

Front Forum includes Member Recommended Supplier listings designed as a resource for members. The purpose of the listings is to provide members with a centralised reference point for pre-approved or recommended service providers.

The Member Recommended Supplier Directory functions as an informational listing only. It is not an advertising marketplace and does not permit promotional messaging within member discussion areas.

Supplier access is subject to the following controls:

  • Access is limited strictly to the Supplier Directory profile submission area;
  • Suppliers do not have access to member discussions, messaging functions, or wider Forum content;
  • Suppliers cannot view member-only discussions or download member data;
  • Suppliers are not permitted to initiate contact with members through the platform.

Front Forum operates in accordance with UK GDPR and the Data Protection Act 2018. Details of personal data processing, lawful basis, and data retention are set out in the Forum’s Privacy Notice, available on the website.

The platform is designed as a restricted-access environment with controlled user permissions and moderated content publication.

2.0 Site Information

  • Primary Domain: https://frontforum.co.uk
  • IP Addresses: Public static IP address assigned by the hosting provider
  • Hosting Provider: Cloudways Managed Hosting Platform
  • Infrastructure Provider: DigitalOcean
  • Data Centre Region: United Kingdom (London)

3.0 Mobile Application

Front Forum provides an optional Progressive Web Application (PWA) mobile application experience. The application can be installed on supported devices and provides members with convenient access and real-time notifications.

Access permissions and security controls remain identical to the web platform and are governed by the same authentication and data protection policies.

The mobile application:

  • Is optional and available only to registered members;
  • Does not provide broader access than authorised web-based permissions;
  • Does not permit supplier access;
  • Is designed primarily to deliver notifications and facilitate convenient member access.

Push notifications are limited to Forum-related updates. The application does not access unrelated device data and does not collect additional personal data beyond that required for member authentication and notification delivery.

The mobile application operates in accordance with the Forum’s Privacy Notice and applicable UK data protection requirements.

4.0 Member Submitted Reference Documents

Members may submit reference documents to share with other members. All submitted documents are reviewed and approved by Forum administrators before being made available.

  • Documents are vetted for appropriateness and compliance with Forum rules;
  • Only approved documents are visible to members; no external users or suppliers can access these files;
  • Uploaded files are subject to server-level malware scanning provided by the hosting platform and require administrator approval before publication.

This process ensures that member-shared resources support professional discussion while maintaining the security and integrity of the Forum.

5.0 Security Information

  • All traffic is encrypted using HTTPS (TLS 1.2 or higher);
  • SSL certificates are automatically managed and renewed;
  • HTTP Strict Transport Security (HSTS) is enforced;
  • Standard web traffic (port 443);
  • No browser plugins required;
  • No desktop software required;
  • Role-based access with administrative oversight;
  • Member uploads are reviewed and approved before publication.

6.0 Contact Details