IT Whitelist Guide

Everything your IT team needs to allow CollaboPoint through corporate firewalls and DNS filters

Last updated: 10 May 2026

1. Introduction

CollaboPoint is a B2B SaaS collaboration platform that provides real-time document editing, video and audio calls, team messaging, task management, and file storage. The platform runs entirely in the browser with no software installation required.

Because CollaboPoint is a relatively new domain, some corporate DNS filters and web proxies may block or restrict access to the platform as an uncategorised or unknown site. This guide provides IT administrators with everything needed to correctly classify and whitelist CollaboPoint across your network security infrastructure.

2. Domains to Whitelist

Add the following domains to your firewall allowlist or proxy bypass rules. Wildcard entries cover all subdomains for the given service.

DomainPurpose
www.collabopoint.comMain application
collabopoint.comApex domain
*.collabopoint.comAll subdomains
*.vercel.appCDN delivery (Vercel)
*.cloudfunctions.netBackend API (Firebase)
*.googleapis.comDatabase and authentication (Firebase)
*.firebaseio.comReal-time database
*.firebaseapp.comFirebase hosting
*.agora.ioVideo and audio calls
*.sd-rtn.comAgora media relay
api.resend.comTransactional email delivery
*.stripe.comPayment processing

3. Ports to Open

TCP 443 is required for all platform features. The UDP ports below are needed for real-time video and audio calls via Agora. If your firewall blocks UDP, calls will fall back to TCP 443 with reduced quality.

ProtocolPort(s)Purpose
TCP443HTTPS (all features)
TCP80HTTP redirect to HTTPS
UDP8001–8010Agora video and audio media
UDP3478, 3479Agora STUN / TURN
TCP4000–4100Agora signalling fallback
UDP1080Agora media

4. DNS Filter Categorisation

CollaboPoint should be categorised as:

Business & Economy / Collaboration Tools / Productivity Software

If your DNS security vendor has flagged or not yet categorised collabopoint.com, you can submit a categorisation request directly through each vendor's portal:

We have published a security.txt file at /.well-known/security.txt and a robots.txt to assist automated categorisation tools.

5. Security Posture

CollaboPoint is built on enterprise-grade infrastructure with the following security controls in place:

  • HTTPS everywhere — all traffic encrypted with TLS 1.3; HSTS enforced with a minimum 1-year duration.
  • SOC 2-aligned practices — access control, logging, and incident response aligned to SOC 2 Trust Service Criteria; formal certification in progress.
  • GDPR compliant — data subject rights, lawful basis for processing, and data minimisation requirements are met. Privacy Policy available at collabopoint.com/privacy.
  • Google Cloud / Firebase infrastructure — primary hosting on Google Cloud Platform, which holds ISO 27001, SOC 2 Type II, and PCI-DSS certifications. Data encrypted at rest with AES-256 via Google Cloud KMS.
  • PCI-DSS Level 1 payments — all payment processing handled by Stripe, a PCI-DSS Level 1 certified provider. CollaboPoint does not store, process, or transmit full card numbers.
  • Data encrypted in transit and at rest — TLS 1.3 in transit; database and file storage encrypted at rest by Google Cloud.

For a full breakdown of our security controls, see our Security Policy.

6. IT Support Contact

If your organisation requires documentation, a security questionnaire, or further assistance with network configuration, our team is happy to help.

Need a security questionnaire or vendor assessment completed? Email it-support@collabopoint.com and our team will respond within one business day.

Related policies

Privacy PolicyTerms of ServiceSecurityGDPRCookie PolicyAcceptable Use