Informationssäkerhet

Informationssäkerhet

På denna sida hittar du all info du behöver om hur datasäkerhet hanteras. Vi börjar med en översikt, och sedan kan du läsa vidare om detaljerna kring infrastruktur och informationssäkerhet.

Gällande GDPR och hur hosting releterar till det, läs om EDPBs senaste beslut om datalagring i USA här: https://edpb.europa.eu/our-work-tools/our-documents/other-guidance/information-note-data-transfers-under-gdpr-united-0_en 

Informationssäkerhetsbeskrivning (Engelska)

Infrastructure Security

Cloud Hosting

The application is hosted on Google Cloud Platform and Amazon Web Services (AWS) in the United States. The GDPR mechanism used as a legal basis for storage in the USA is Standard Contractual Clauses. Both Google and AWS have audited security and compliance programs.

Network Security

Multiple layers of filtering are applied to all connections. Network access controls and firewalls are in place to prevent unauthorized access. Firewall rules undergo periodic reviews.

Configuration Management

The infrastructure is automated and scalable. Server configurations are controlled through images and files. Any deviations from baseline settings are corrected within 30 minutes.

Logging

All actions and events within the application are logged. Logs are indexed and stored. Access to log storage is restricted to authorized engineers.

Alerting and Monitoring

Automated monitoring and alerting mechanisms are in place for detecting anomalies such as high error rates or potential attacks.

Application Security

Web Application Defenses

The application is protected by firewall and application security measures. Monitoring tools are in place to alert on malicious behavior, following the Open Web Application Security Project (OWASP) Top 10 guidelines. DDoS protection is also included.

Development and Release Management

The application uses a continuous delivery approach. Code undergoes reviews, testing, and static analysis before deployment. Approved code moves to a QA environment before being promoted to production. Automated deployments allow for quick rollbacks.

Vulnerability Management

A multi-layered approach to vulnerability management is used, employing industry-recognized tools and threat feeds. Regular vulnerability scans and annual penetration tests are performed. Findings are assessed and prioritized for mitigation.

Customer Data Protection

Data Classification

Customers are responsible for capturing appropriate data and classifying it using the features inside the application.

Tenant Separation

Customer data is logically separated with unique IDs. Authorization rules are integrated into the architecture and are continuously validated. Activities such as authentication changes and user access are logged.

Encryption

Data in transit is encrypted using TLS v1.2 or 1.3 and 2,048-bit keys. For data at rest, AES-256 encryption is used. User passwords are hashed and encrypted.

Key Management

Encryption keys are securely managed. TLS private keys for transit encryption are managed through a content delivery partner. At-rest encryption keys are stored in a hardened Key Management System (KMS) and are rotated depending on data sensitivity. In general, TLS certificates are renewed annually. We cannot at this time use customer supplied encryption keys.

Data Retention and Data Deletion

The application keeps customer data for the duration of active customer status. Written requests for specific data deletion can be made by both current and former customers, and these requests are complied with as mandated by privacy laws. Log data and related metadata are retained for security, compliance, or legal requirements. The application doesn’t allow for custom data retention policies.

Data Backup and Disaster Recovery

System Reliability and Recovery

The application is designed to minimize downtime by employing redundancy. Infrastructure is distributed across multiple availability zones and virtual private clouds. All components are set up for point-in-time recovery.

System Backups

Regular backups follow set schedules. Seven days of database backups are maintained for easy restoration. Monitoring ensures successful backup execution, and alerts are generated for any exceptions.

Physical Backup Storage

No physical infrastructure or storage media are used as everything is hosted on public cloud services.

Backup Protections

Access to all backups is controlled by restrictions and WORM (Write Once, Read Many) protections within the application’s networks, as well as file system access control lists.

Customer Data Backup Restoration

Customers cannot directly access the product infrastructure for failovers. Disaster recovery is managed by the engineering teams. However, the application allows for some level of customer-driven data recovery like restoring deleted contacts or reverting changes to web pages.

For those who want additional backups, the application offers various export options and public APIs for data synchronization.

Identity and Access Control

Product User Management

The application permits finely-tuned authorization rules. Customers have the ability to manage their portal’s users, set appropriate permissions, and limit access as needed.

Product Login Protections

Users can sign into their accounts using the application’s native login, which adheres to a standardized password policy requiring a mix of character types and a minimum length of 8 characters. Two-factor authentication is available, and portal administrators have the option to require it for all users.

Internal resources (not reachable for customers):Internal GDPR overview. Internal information security info

Internal

100%