Third Party Index

Snapshot 17550

Document
Security page
URL
https://www.facilityos.com/tech-review-summary
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
55464 bytes
SHA-256 (raw)
58c219d2973615dd3262316ed52746a7c4e297fc318f607bf5edf52334550d93
SHA-256 (normalized text)
26be455f9a8c37421851af9dd4d3d4f96c60d3b3fa44c6239c7f36e64886cfa1

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security and Redundancy Overview Summary
Version 4
FacilityOS Solution Overview
Introduction
FacilityOS is an enterprise-grade product developed, hosted and tested using the highest industry standards, exceeding most requirements.
FacilityOS is a cloud-based secure facility management system comprising a self-serve device or kiosk and centralized hosting. The entire solution is managed through the web-based portal which allows administrators to manage the specific features and details of each installation as well as generate reports pertaining to the visitor activity at each site.
This document serves as a review of provided technology with emphasis on the security and redundancy of the solution.
Following is a summary; detailed Technology Review document is available on request, pending executed NDA. Certain items require specific license subscriptions and/or may be subject to additional costs.
Our Employees and Workspace Environment
All FacilityOS employees are screened with extensive background and criminal record checks prior to hiring.
All employees are trained in the company’s privacy, safety, security and other workplace policies.
All equipment and data handling follows common security practices:
Applications and hardware are inventoried.
Access is role based with global policies enforced (Active Directory).
Ports are blocked.
Production data is not locally stored.
Devices are tracked and centrally managed.
How We Built FacilityOS
FacilityOS is designed and built in Toronto, Canada.
We follow Agile and Scrum methodology.
We adhere to OWASP Secure Coding Practices (www.owasp.org).
All software development is version and source controlled.
Three separate environments are maintained (Production, Development, Staging) with restricted access.
Our development teams do not have access to customer data.
Microsoft Technologies are used to control access (Azure Active Directory).
Your Data Security, Privacy and Confidentiality
All customer data is considered private and confidential and is protected by the privacy policy.
Custom agreements and privacy policies are available.
Customers can elect to have the data stored in a specific geo-location.
Customers can request custom data retention policies; expired data is deleted using automated database procedures, DOD 5220.22M available on request.
All data is fully encrypted at rest and during transmission.
All access is controlled and monitored.
Customer data is segmented, and access is limited to owner(s) only.
Passwords are hashed and cannot be recovered.
Visitor Data Security, Privacy and Confidentiality
Visitor data falls under the main system guidelines for data security.
Global data privacy standards are supported (i.e. GDPR).
FacilityOS offers a strong compliance platform which plugs into an organization’s global compliance initiatives, implementation of which is managed by the Client.
Geo-distributed data storage is available to comply with local rules.
Product, Security, Continuity
FacilityOS is hosted on Microsoft Azure (Multiple GEO locations available). Additional hosting options are available utilizing local vendors and our own dedicated hosting environments.
All data centers adhere to common industry standards for data protection and policies. Certifications are geo/site specific and cover PCI DSS, ISAE 3402 Type II, SOC 2 Type II and CSAE 3416 Type II to name a few.
Please visit Azure trust center for a list of supported certifications and standards: https://azure.microsoft.com/en-us/support/trust-center/
Non-Azure hosted, site specific certifications are provided on request.
Geo/region specific hosting is available.
Data and services are fully backed and are fully redundant with an availability of 99.9% uptime guarantee.
Server / Platform structure is hosting dependent and available on request.
FacilityOS supports Offline mode (no network connection).
FacilityOS packages can be deployed with a fully redundant cellular connection.
More on Encryption
All access to web services uses HTTPS (TLS 1.2+).
Device to server communication is encrypted with a private key, delivered over secure channel (HTTPS) and tokenized using device unique identifier and other undisclosed variables.
Connectivity
FacilityOS can be deployed using a combination of cellular, wireless, and ethernet connections. Exact configuration is dependent on each client’s redundancy and hardware requirements.
FacilityOS uses standard ports and services which makes it a “plug ‘n play” product when connected to the client’s infrastructure. In most cases, no additional configurations are required.
Clients managing highly restricted environments will need to ensure that traffic to *.goilobby.com bypasses proxies and is whitelisted on the firewall(s).
In some cases, subject to client’s wireless network policies, FacilityOS may need to be provisioned with client’s wireless network certificates.
We recommend setting up all equipment using static IPs. This makes for a more robust and stable setup. Our preference is to let the client’s DHCP server assign static IPs using provided MAC addresses.
Subcontractors and Third Parties
FacilityOS core engineering function is completely in-house, in our Toronto office.
The use of any subcontractors puts them in scope of our overall standards for security and privacy. Specifically:
Each subcontractor must be classified based on their risk.
Their policies and standards must meet our requirements.
Their policies and standards must be reviewed as frequently as required by their classification within our policies and controls.
FacilityOS requires the use of Third Parties for provision and delivery of some of its services. Specifically:
Microsoft Azure – hosting provider for the FacilityOS Platform
https://gallery.technet.microsoft.com/Overview-of-Azure-c1be3942
Twilio – SMS and VOICE message delivery
https://www.twilio.com/gdpr
https://www.twilio.com/security
https://s3.amazonaws.com/ahoy-assets.twilio.com/Whitepapers/Twilio_Whitepaper_GDPR.pdf
https://interactive.twilio.com/Global/FileLib/PDFs/Twilio_Trust_&_Security_White_Paper_FINAL_09102021.pdf
Vonage – SMS message delivery
https://www.vonage.com/security/communication-apis/
Sendgrid - Email delivery
https://sendgrid.com/resource/general-data-protection-regulation/
https://sendgrid.com/policies/privacy/privacy-shield-certification/
Mailgun – Email delivery
https://www.mailgun.com/security/
We encourage customers to review the above-mentioned content for compliance with their internal requirements.
Payments
All credit card transactions are processed in a PCI-DSS certified environment to ensure compliance and security.
Insurance
FacilityOS employs business continuity, data theft and breach insurances covering liability in excess of $2,000,000. Certificate available on request.