Adeptis

Security and GDPR consent, handled properly

Mandatory two-factor login, permissions per user, and GDPR consent recorded by channel and media group. Built for the governance a publisher's data demands.

The Adeptis two-factor settings card confirming two-factor authentication is enabled, showing backup codes remaining and buttons for new backup codes and reset or re-enrol

A publisher's database is mostly personal data: names, job titles, work addresses, email addresses and what each person agreed to. Lose control of it and you have a problem with your readers, your advertisers and the ICO, probably in that order.

Adeptis is built with that in mind. Access, consent and audit trails are part of the system, not a bolt-on, and none of it relies on people remembering to switch a setting on.

Two-factor login for everyone

Every Adeptis user signs in with two-factor authentication. It isn't optional, so nobody ends up as the weak link because they found it a nuisance.

  • Enrolment with an authenticator app by scanning a QR code.
  • Single-use backup codes, so a lost phone doesn't lock someone out for good.
  • Lockout after repeated failed attempts.

Users can generate new backup codes or reset and re-enrol from their own security page.

Sensible security underneath

The parts you don't see matter as much as the login screen:

  • Passwords are hashed with bcrypt, never stored as plain text.
  • Every form that changes data is protected against cross-site request forgery (CSRF).
  • Database access is parameterised throughout, which guards against SQL injection.

None of that is exotic. It's what good software should do, and Adeptis does it by default.

Permissions per user

Not everyone needs to see everything. Permissions in Adeptis are set per user, and an account can be restricted to a single screen.

The gone-away desk is the obvious example. Whoever opens the returned post can key reader numbers and mark gone-aways without access to subscriptions, advertising or anything else.

Consent sits on each contact's record, on its own GDPR tab in the CRM.

An Adeptis contact record with tabs for overview, activity, related contacts, circulation, subscriptions, email lists, demographics and GDPR, with personal details blurred
Consent lives on the contact record, on its own GDPR tab

It's recorded per media group, separately for your own use and for third-party use, and by channel: email, post, phone and SMS. So "happy to get our newsletter by email, but not third-party offers by phone" is something the system can hold, not a note in a free-text box.

Marketing opt-in is captured at the point of sale on online orders, so you know what a new subscriber agreed to from day one.

This one catches a lot of publishers out. An email that bounces is a delivery problem. An unsubscribe is someone withdrawing permission. They're not the same, and treating them as the same causes trouble both ways.

Adeptis keeps reachability (bounces and suppression) separate from consent (unsubscribes). A full mailbox doesn't get recorded as someone saying no, and someone who said no doesn't get mailed again because their address started working. Email insight reports on bounces with that distinction intact.

Audit trails where they matter

When records change, you can see what happened. The gone-away desk keeps its own audit trail, with an undo for mistakes. The de-dupe tools merge records in one transaction and keep the full history. For an ABC audit or a subject access request, that's the difference between an answer and a guess.

The company behind it

Adept Data Services is Cyber Essentials certified and registered with the ICO. The people who build Adeptis are our in-house UK development team, and the people who'll help you use it have spent decades handling publishers' subscriber data.

If you're a larger group needing finer-grained configuration across several brands, Avio security and administration covers that, for larger publishers and groups.

Book an Adeptis demo and bring your data protection questions. We'd rather answer them up front.

Questions

Is two-factor authentication optional?

No. It's mandatory for every user, with an authenticator app, single-use backup codes and lockout after repeated failed attempts.

Can we limit what each member of staff can see?

Yes. Permissions are set per user, down to accounts that can only use a single screen, such as the gone-away desk.

How is GDPR consent recorded?

Per media group, for internal and third-party use, by channel: email, post, phone and SMS. Marketing opt-in is captured on online orders too.

Does a bounced email remove someone's consent?

No. Reachability (bounces and suppression) is kept separate from consent (unsubscribes), so a delivery problem isn't mistaken for a withdrawn permission.

See Adeptis working on your own kind of data

Book a demo and we'll walk you through Adeptis, concentrating on the parts that matter to you. No hard sell.