Frontline Performance Group recognises that the confidentiality, integrity and availability of information and data created, maintained and hosted by us are vital to the success of the business and privacy of our partners.
As a service provider/product, we understand the importance in providing clear information about our security practices, tools, resources and responsibilities within IN-Gauge so that our customers can feel confident in choosing us as a trusted provider.
This Security Posture highlights high-level details about our steps to identify and mitigate risks, implement best practices, and continuously develop ways to improve.
Founded in 1993
Here are the controls implemented at IN-Gauge to ensure compliance, as a part of our security program.
Production System User Review
Situational Awareness For Incidents
Vulnerability Remediation Process
Centralized Management of Flaw Remediation Processes
Single Sign On
IN-Gauge provides enterprise-grade Single Sign-On (SSO) capabilities to ensure secure and seamless user authentication. The platform supports standard authentication protocols such as SAML 2.0, enabling direct integration with leading Identity Providers (IdPs) including Okta, Microsoft Entra ID (Azure AD), Ping Identity, and Google Workspace.
By leveraging existing corporate authentication systems, IN-Gauge centralizes user access management, reduces password reuse, and enforces organizational security controls such as Multi-Factor Authentication (MFA) and Conditional Access Policies. This integration streamlines user provisioning, strengthens access governance, and maintains compliance with enterprise security and data protection standards — all while delivering a frictionless login experience for end users.
Role Based Access Controls
IN-Gauge employs application-level Role-Based Access Control (RBAC) to define and manage user permissions within the platform. Roles are assigned directly inside the application based on operational responsibilities such as Customer Leadership, General Manager, Program Champion, Location Manager, and Frontline Associate.
Each role has a predefined level of visibility and access to data, ensuring users only interact with the information and functionality necessary to perform their duties. Permissions are enforced at the application layer, preventing unauthorized access or configuration changes outside of a user’s designated scope.
Role assignments and changes are managed by authorized administrators within the IN-Gauge platform. All access updates are logged for traceability, and permissions are periodically reviewed to maintain proper alignment with user responsibilities. This structure supports least-privilege principles and ensures consistent, controlled access to data and features across all customers and environments.
Identity Validation
Termination of Employment
Multi-factor Authentication
Encrypting Data At Rest
Inventory of Infrastructure Assets
Data Backups
Testing for Reliability and Integrity
Impact analysis
Limit Network Connections
External System Connections
Transmission Confidentiality
Anomalous Behavior
Capacity & Performance Management
Data used in Testing
Centralized Collection of Security Event Logs
Conspicuous Link To Privacy Notice
Secure system modification
Approval of Changes
Unauthorized Activities
Malicious Code Protection (Anti-Malware)
Full Device or Container-based Encryption
Endpoint Security Validation
Session Lock
Endpoints Encryption
Code of Business Conduct
Organizational Structure
Roles & Responsibilities
Competency Screening
Personnel Screening
New Hire Policy Acknowledgement
Security & Privacy Awareness
Performance Review
Periodic Policy Acknowledgement
Automated Reporting
Incident Reporting Assistance
Risk Framing
Risk Assessment
Fraud
Third-Party Criticality Assessments
Assigned Cybersecurity & Privacy Responsibilities
Internal Audit using Sprinto
Periodic Review & Update of Cybersecurity & Privacy Program
Management Review of Org Chart
Management Review of Risks
Management Review of Third-Party Risks
Subservice organization evaluation
Segregates Roles and Responsibilities
Testing
Asset Ownership Assignment
New Hire Security & Privacy Training Records
Periodic Security & Privacy Training Records
Updates During Installations / Removals
Inventory of Endpoint Assets