What this site is
HPS Guard Portal is the operational system used by HPS Security Services officers, managers and directors, and by client site managers who are given a login. It records shift handovers, incident reports, patrol evidence and shift rotas. It is a private business system, not a public consumer site, and it hosts no advertising, tracking or user-generated public content.
Encryption
Every page and every request is served over HTTPS only, with HTTP Strict Transport Security enforced. Data is encrypted in transit and encrypted at rest in the database and file storage.
Access control
There is no public sign-up. Accounts are created only by an HPS director, who issues a one-time password that the user must replace at first sign-in. Every account holds a defined role (director, manager, officer or client) and row-level database rules restrict each account to the sites and records it is entitled to see. Client logins can only ever see their own site.
Data protection
Records are processed under UK GDPR as part of the delivery of contracted security services. Data held includes officer names and SIA badge numbers, shift and patrol records, incident reports and photographic evidence taken on site. Records are visible to the relevant client site manager only where HPS has enabled that category for their site.
For IT and network teams
The portal is a single first-party domain, hpsservicesstaffportal.org, served from a UK/EU content delivery network. All application code, styles, fonts and map assets are served from that same domain. Outbound calls are limited to the portal's own secured backend for sign-in, data and file storage, and to OpenStreetMap tile servers when a patrol map is displayed. To allow staff and site managers to use the portal, please categorise hpsservicesstaffportal.org as a business or workforce application and permit it in the web filter.
Reporting a security concern
If you believe you have found a vulnerability or a data-protection issue, email security@hpsservicesstaffportal.org with the details. We will acknowledge and investigate. A machine-readable copy of this contact is published at /.well-known/security.txt.