Your alerts never leave your network. Here’s the security model, in the detail IT expects.
- Alert path
- Your LAN
- Cloud
- Licensing and reporting
- Port
- TCP 8001
- Docs
- Architecture pack

Where do alerts travel?
Client to server on your LAN only (default TCP 8001), never routed off your network. Server to cloud is encrypted in transit with TLS. The cloud is never in the live alert path.
What goes to the cloud?
Licensing, downloads, and reporting records (timestamps, workstation identity, alert states, notification outcomes), sent by the server only, over HTTPS. By default, clients contact only your server.
What about patient data?
Duress Alert has no patient or clinical fields. Only workstation identity, timestamps and alert states.
Security assurance
We publish our architecture and data flows in full, so your IT team can assess us directly. Ask for the technical pack: architecture diagram, data-flow document, network requirements and our security FAQ.
Firewall & network
| Path | Scope | Notes |
|---|---|---|
| Client ↔ server | Local network only | Your local network only, on a configurable port (default TCP 8001). By default, clients contact only your server. |
| Server → cloud | Outbound HTTPS | Duress Alert API endpoints, licensing, downloads and reporting only. Never in the live alert path. |
| Webhooks | Outbound | Slack, Microsoft Teams or Google Chat, plus SMTP / Microsoft 365 / Gmail email. |
| Windows Firewall | Auto-configured | Server sets the required rules where it has rights, and shows status either way. |
Licence integrity
Licences are signed and installed locally on your server. Licence checks include signature, expiry, server fingerprint and client capacity. All client configuration is signed and distributed from your server, there are no local settings for staff to alter, and no configuration drift between machines.
What happens if a licence lapses?
In practice it doesn’t get the chance. Licences auto-renew by card by default, renewal is self-serve in the portal, and your admins are warned well before expiry, and because renewals run through our cloud, we see the same status and reach out too. If a licence ever does expire, alerting stops until it’s renewed, and every client turns grey so the state is visible on every screen. Transparency at every layer; no silent failure.
You can see when something needs attention

Tell us about your site.
Tell us your team size and setting, and we’ll show you how Duress Alert works on your own desks and what a rollout looks like. We get back to you quickly.
For the deep detail, request the technical pack (email only).
Hand this to your IT reviewer.
Request the technical pack, or ask us anything your security review needs.
