Controls (84)

Here are the controls implemented at subprocessore to ensure compliance, as a part of our security program.

Product security (12)

Entity ensures that critical Cloud Service Providers can enforce the password management requirements defined by the Entity

Entity ensures that encryption controls available with critical Cloud Service Providers are assessed and implemented as per the Encryption Policy

Entity ensures that critical Cloud Service Providers are capable to dispose or reuse resources in accordance with the Entity's disposal and reuse requirements

Entity ensures that the change management process can accommodate the impact of changes made by critical Cloud Service Providers

The Entity monitors the capacity and performance of critical Cloud Service Providers, thereby ensuring that the CSP offering is aligned with capacity requirements defined by the Entity

The Entity ensures that the backup capabilities of critical Cloud Service Providers (where applicable) are assessed according to the Entity's requirements related to data backups

Entity ensures that the event logging capabilities of critical Cloud Service Providers are aligned to the requirements defined by the Entity

The Entity ensures that critical Cloud Service Providers can log privileged operations executed by the Entity. The Entity also defines if the logging capabilities provided by the CSPs are adequate or if additional logging solutions should be implemented

Entity's Infosec officer reviews and approves the list of people with access to production console annually

Entity maintains a record of information security incidents.

Entity identifies vulnerabilities on the Company platform through the execution of regular vulnerability scans.

Entity tracks all vulnerabilities, and resolves them as per the Vulnerability Management Policy.

Data security (15)

The Entity ensures that all software installed on cloud solutions is appropriately licensed

Entity maintains a matrix that outlines which system components should be accessible to staff members based on their role.

Staff access to Entity's systems are made inaccessible in a timely manner as a part of the offboarding process.

Entity ensures that access to the production databases is restricted to only those individuals who require such access to perform their job functions.

Entity requires that all staff members with access to any critical system is protected with a secure login mechanism such as Multifactor-authentication

Entity's Senior Management or the Information Security Officer periodically reviews and approves the list of people with access to the entity's system

Entity's Senior Management or the Information Security Officer periodically reviews and approves the list of people with Administative access to the entity's system

All production database[s] that store customer data are encrypted at rest.

Entity maintains a list of production infrastructure assets and segregates production assets from its staging/development assets.

Entity backs-up their production databases periodically

Entity's data backups are restored and tested annually

Entity ensures appropriate procedures are in place to ensure compliance with regulatory requirements related to transfer of personal data outside of the region from which it is collected

Entity maintains an inventory of categories of personal information collected along with its usage, sources and specific purposes for collection as per regulatory requirements ("Record of Processing Activities") and reviews it on an annual basis

Entity ensures regulatory requirements regarding user consent are met prior to processing personal data

Entity ensures that Subject Access Requests are being honoured in accordance with the Privacy Policy

Network security (9)

Entity ensures that customer data used in non-Production environments requires the same level of protection as the production environment

The entity systems generate information that is reviewed and evaluated to determine impacts to the functioning of internal controls.

The Entity acquires information on the time service provider used by critical Cloud Service Providers

Entity ensures that critical Cloud Service Proviers can meet the defined requirements related to network segregation and tenant separation

Entity ensures that the production databases access and Secure Shell access to infrastructure entities are protected from public internet access

Every Production host is protected by a firewall with a deny-by-default rule. Deny by default rule set is a default on the Entity's cloud provider.

User access to the entity's application is secured using https (TLS algorithm) and industry standard encryption.

Entity's infrastructure is configured to generate audit events for actions of interest related to security which are reviewed and analyzed for anomalous or suspicious activity

Entity's Production assets are continuously monitored to generate alerts and take immediate action where necessary

App security (4)

Entity uses Sprinto, a continuous monitoring system, to alert the security team to update the access levels of team members whose roles have changed

Entity displays the most current information about its services on its website, which is accessible to its customers.

Entity uses a change management system to track, review and log all changes to the application code.

Entity's change management system is configured to enforce peer reviews for all planned changes. For all code changes, the reviewer must be different from the author.

Endpoint security (5)

Entity requires that all critical endpoints are encrypted to protect them from unauthorised access

Entity requires that all endpoints with access to production systems are protected by malware-protection software

Entity requires that all company-owned endpoints be encrypted to protect them from unauthorised access

Entity requires that all employee endpoints be audited once a quarter to ensure security patches are applied and the Operation System version is current, or the next most current.

Entity requires that all company owned endpoints be configured to auto-screen-lock after 15 minutes of inactivity

Corporate security (39)

Entity has established behavioral standards which are defined in the Code of Business Conduct and makes it available to all staff members on the company employee portal

Entity appoints a Privacy Officer to assess and facilitate the entity's compliance with relevant regulatory requirements

Entity requires that all staff members review and acknowledge company policies annually

Entity's senior management reviews and approves the Privacy Policy and Terms of Service periodically

Entity has provided information to employees, via the Information Security Policy, on how to report failures, incidents, concerns, or other complaints related to the services or systems provided by the Entity in the event there are problems.

Entity appoints an owner of Infrastructure, who is responsible for all assets in the inventory

Entity has provided information to customers on how to report failures, incidents, concerns, or other complaints related to the services or systems provided by the Entity in the event there are problems.

The Entity has defined the security requirements for the usage of cloud security services and evaluates the cloud service providers to identify if the providers are meet the defined specifications

The Entity has assessed and validated the software development practices of cricial Cloud Service Providers

The Entity ensures that the information security roles and responsibilities are clearly defined based on the shared responsibility model and the terms and conditions proposed by critical Cloud Service Providers

The Entity ensures that its incident response procedures are updated to reflect the usage of cloud service providers. Entity has identified how to report incidents to Cloud Service Providers, as well as how to respond to an incident reported by the Cloud Service Providers

The Entity assesses and validates the controls implemented by critical Cloud Service Providers for the protection of data collected and stored by the Cloud Service Provider

The Entity requests an external security certification of an independent audit report of the implemented and claimed information security controls for all critical Cloud Service Providers

The Entity has formulated an exit strategy and evaluated the documented process of critical Cloud Service Providers related to the return and removal of the Entity's data

The Entity ensures that its disaster recovery plans are updated with scenarios addressing possible failure of critical cloud-based resources or services

Entity performs a formal risk assessment exercise annually, as detailed out in the Risk Assessment and Management Policy, to identify threats that could impair systems' security commitments and requirements

Each risk is assessed and given a risk score in relation to the likelihood of it occurring and the potential impact on the security, availability and confidentiality of the Company platform. Risks are mapped to mitigating factors that address some or all of the risk.

Entity maintains an Organizational Structure to define authorities, facilitate information flow and establish responsibilities

Entity considers the potential for fraud when assessing risks. This is an entry in the risk matrix.

Entity performs a formal vendor risk assessment exercise annually, as detailed out in the Risk Assessment and Management Policy, to identify vendors that are critical to the systems' security commitments and requirements

Entity's Senior Management assigns the role of Information Security Officer who is delegated the responsibility of planning, assessing, implementing and reviewing the internal control environment.

Entity uses Sprinto, a continuous monitoring system, to track and report the health of the information security program to the Information Security Officer and other stakeholders

Entity's Senior Management reviews and approves the state of the Information Security program annually

Entity's Senior Management reviews and approves the Organizational Chart for all employees annually.

Entity's Senior Management reviews and approves the "Risk Assessment Report" annually.

Entity's Senior Management reviews and approves the "Vendor Risk Assessment Report" annually.

Entity ensures clarity in job responsibilities for client serving, IT and engineering positions (via OKRs, Job Descriptions etc.) to increase the operational effectiveness of the organisation

Entity reviews and evaluates all subservice organizations periodically, to ensure commitments to Entity's customers can be met

Entity's Senior Management segregates responsibilities and duties across the organization to mitigate risks to the services provided to its customers

Entity ensures that new hires have been duly evaluated for competence in their expected job responsibilities

Entity ensures that new hires go through a background check as part of their onboarding process

Entity requires that new staff members review and acknowledge company policies as part of their onboarding. This ensures they understand their responsibilities and are willing to comply with them.

Entity has established an Information Security Awareness training, and its contents are available for all staff on the company employee portal.

Entity ensures that appropriate remediation measures are in place when personal data is shared with vendors as a part of its processing activities

Entity conducts Data Protection Impact Assessments periodically in order to assess the regulatory risks associated with processing of personal data

Entity appoints a EU Representative to serve as a point of contact between EU authorities, data subjects and the organization

Entity requires that all employees in client serving, IT, Engineering and Information Security roles are periodically evaluated regarding their Job responsibilities

Entity ensures that the Disaster Recovery Plan is tested periodically and learnings documented

Entity maintains a list of all contractual obligations based on customer contracts