subprocessore recognises that the confidentiality, integrity and availability of information and data created, maintained and hosted by us are vital to the success of the business and privacy of our partners.
As a service provider/product, we understand the importance in providing clear information about our security practices, tools, resources and responsibilities within subprocessore so that our customers can feel confident in choosing us as a trusted provider.
This Security Posture highlights high-level details about our steps to identify and mitigate risks, implement best practices, and continuously develop ways to improve.
added a new text for testing custom domain
Here are the controls implemented at subprocessore to ensure compliance, as a part of our security program.
Entity ensures that critical Cloud Service Providers can enforce the password management requirements defined by the Entity
Entity ensures that encryption controls available with critical Cloud Service Providers are assessed and implemented as per the Encryption Policy
Entity ensures that critical Cloud Service Providers are capable to dispose or reuse resources in accordance with the Entity's disposal and reuse requirements
Entity ensures that the change management process can accommodate the impact of changes made by critical Cloud Service Providers
The Entity monitors the capacity and performance of critical Cloud Service Providers, thereby ensuring that the CSP offering is aligned with capacity requirements defined by the Entity
The Entity ensures that the backup capabilities of critical Cloud Service Providers (where applicable) are assessed according to the Entity's requirements related to data backups
Entity ensures that the event logging capabilities of critical Cloud Service Providers are aligned to the requirements defined by the Entity
The Entity ensures that critical Cloud Service Providers can log privileged operations executed by the Entity. The Entity also defines if the logging capabilities provided by the CSPs are adequate or if additional logging solutions should be implemented
Entity's Infosec officer reviews and approves the list of people with access to production console annually
Entity maintains a record of information security incidents.
Entity identifies vulnerabilities on the Company platform through the execution of regular vulnerability scans.
Entity tracks all vulnerabilities, and resolves them as per the Vulnerability Management Policy.
The Entity ensures that all software installed on cloud solutions is appropriately licensed
Entity maintains a matrix that outlines which system components should be accessible to staff members based on their role.
Staff access to Entity's systems are made inaccessible in a timely manner as a part of the offboarding process.
Entity ensures that access to the production databases is restricted to only those individuals who require such access to perform their job functions.
Entity requires that all staff members with access to any critical system is protected with a secure login mechanism such as Multifactor-authentication
Entity's Senior Management or the Information Security Officer periodically reviews and approves the list of people with access to the entity's system
Entity's Senior Management or the Information Security Officer periodically reviews and approves the list of people with Administative access to the entity's system
All production database[s] that store customer data are encrypted at rest.
Entity maintains a list of production infrastructure assets and segregates production assets from its staging/development assets.
Entity backs-up their production databases periodically
Entity's data backups are restored and tested annually
Entity ensures appropriate procedures are in place to ensure compliance with regulatory requirements related to transfer of personal data outside of the region from which it is collected
Entity maintains an inventory of categories of personal information collected along with its usage, sources and specific purposes for collection as per regulatory requirements ("Record of Processing Activities") and reviews it on an annual basis
Entity ensures regulatory requirements regarding user consent are met prior to processing personal data
Entity ensures that Subject Access Requests are being honoured in accordance with the Privacy Policy
Entity ensures that customer data used in non-Production environments requires the same level of protection as the production environment
The entity systems generate information that is reviewed and evaluated to determine impacts to the functioning of internal controls.
The Entity acquires information on the time service provider used by critical Cloud Service Providers
Entity ensures that critical Cloud Service Proviers can meet the defined requirements related to network segregation and tenant separation
Entity ensures that the production databases access and Secure Shell access to infrastructure entities are protected from public internet access
Every Production host is protected by a firewall with a deny-by-default rule. Deny by default rule set is a default on the Entity's cloud provider.
User access to the entity's application is secured using https (TLS algorithm) and industry standard encryption.
Entity's infrastructure is configured to generate audit events for actions of interest related to security which are reviewed and analyzed for anomalous or suspicious activity
Entity's Production assets are continuously monitored to generate alerts and take immediate action where necessary
Entity uses Sprinto, a continuous monitoring system, to alert the security team to update the access levels of team members whose roles have changed
Entity displays the most current information about its services on its website, which is accessible to its customers.
Entity uses a change management system to track, review and log all changes to the application code.
Entity's change management system is configured to enforce peer reviews for all planned changes. For all code changes, the reviewer must be different from the author.
Entity requires that all critical endpoints are encrypted to protect them from unauthorised access
Entity requires that all endpoints with access to production systems are protected by malware-protection software
Entity requires that all company-owned endpoints be encrypted to protect them from unauthorised access
Entity requires that all employee endpoints be audited once a quarter to ensure security patches are applied and the Operation System version is current, or the next most current.
Entity requires that all company owned endpoints be configured to auto-screen-lock after 15 minutes of inactivity
Entity has established behavioral standards which are defined in the Code of Business Conduct and makes it available to all staff members on the company employee portal
Entity appoints a Privacy Officer to assess and facilitate the entity's compliance with relevant regulatory requirements
Entity requires that all staff members review and acknowledge company policies annually
Entity's senior management reviews and approves the Privacy Policy and Terms of Service periodically
Entity has provided information to employees, via the Information Security Policy, on how to report failures, incidents, concerns, or other complaints related to the services or systems provided by the Entity in the event there are problems.
Entity appoints an owner of Infrastructure, who is responsible for all assets in the inventory
Entity has provided information to customers on how to report failures, incidents, concerns, or other complaints related to the services or systems provided by the Entity in the event there are problems.
The Entity has defined the security requirements for the usage of cloud security services and evaluates the cloud service providers to identify if the providers are meet the defined specifications
The Entity has assessed and validated the software development practices of cricial Cloud Service Providers
The Entity ensures that the information security roles and responsibilities are clearly defined based on the shared responsibility model and the terms and conditions proposed by critical Cloud Service Providers
The Entity ensures that its incident response procedures are updated to reflect the usage of cloud service providers. Entity has identified how to report incidents to Cloud Service Providers, as well as how to respond to an incident reported by the Cloud Service Providers
The Entity assesses and validates the controls implemented by critical Cloud Service Providers for the protection of data collected and stored by the Cloud Service Provider
The Entity requests an external security certification of an independent audit report of the implemented and claimed information security controls for all critical Cloud Service Providers
The Entity has formulated an exit strategy and evaluated the documented process of critical Cloud Service Providers related to the return and removal of the Entity's data
The Entity ensures that its disaster recovery plans are updated with scenarios addressing possible failure of critical cloud-based resources or services
Entity performs a formal risk assessment exercise annually, as detailed out in the Risk Assessment and Management Policy, to identify threats that could impair systems' security commitments and requirements
Each risk is assessed and given a risk score in relation to the likelihood of it occurring and the potential impact on the security, availability and confidentiality of the Company platform. Risks are mapped to mitigating factors that address some or all of the risk.
Entity maintains an Organizational Structure to define authorities, facilitate information flow and establish responsibilities
Entity considers the potential for fraud when assessing risks. This is an entry in the risk matrix.
Entity performs a formal vendor risk assessment exercise annually, as detailed out in the Risk Assessment and Management Policy, to identify vendors that are critical to the systems' security commitments and requirements
Entity's Senior Management assigns the role of Information Security Officer who is delegated the responsibility of planning, assessing, implementing and reviewing the internal control environment.
Entity uses Sprinto, a continuous monitoring system, to track and report the health of the information security program to the Information Security Officer and other stakeholders
Entity's Senior Management reviews and approves the state of the Information Security program annually
Entity's Senior Management reviews and approves the Organizational Chart for all employees annually.
Entity's Senior Management reviews and approves the "Risk Assessment Report" annually.
Entity's Senior Management reviews and approves the "Vendor Risk Assessment Report" annually.
Entity ensures clarity in job responsibilities for client serving, IT and engineering positions (via OKRs, Job Descriptions etc.) to increase the operational effectiveness of the organisation
Entity reviews and evaluates all subservice organizations periodically, to ensure commitments to Entity's customers can be met
Entity's Senior Management segregates responsibilities and duties across the organization to mitigate risks to the services provided to its customers
Entity ensures that new hires have been duly evaluated for competence in their expected job responsibilities
Entity ensures that new hires go through a background check as part of their onboarding process
Entity requires that new staff members review and acknowledge company policies as part of their onboarding. This ensures they understand their responsibilities and are willing to comply with them.
Entity has established an Information Security Awareness training, and its contents are available for all staff on the company employee portal.
Entity ensures that appropriate remediation measures are in place when personal data is shared with vendors as a part of its processing activities
Entity conducts Data Protection Impact Assessments periodically in order to assess the regulatory risks associated with processing of personal data
Entity appoints a EU Representative to serve as a point of contact between EU authorities, data subjects and the organization
Entity requires that all employees in client serving, IT, Engineering and Information Security roles are periodically evaluated regarding their Job responsibilities
Entity ensures that the Disaster Recovery Plan is tested periodically and learnings documented
Entity maintains a list of all contractual obligations based on customer contracts