Third Party Index

Snapshot 20772

Document
Security page
URL
https://www.moogsoft.com/security/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
100563 bytes
SHA-256 (raw)
8ccb74eed77c2166984491f4229b762969ac50358ea17ca919e4e1bbfa774577
SHA-256 (normalized text)
95ccb89a4be3cea400aa1f18580b723ad3a313bd6b6e654c244abcb5dd7ee2e1

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security
alison2023-04-19T00:44:23-07:00
Moogsoft Security Policy
Security
Web Application Security
Compliance
Contact Us
Security
Moogsoft integrates security into every phase of its Software Development Lifecycle (SDLC). From the architecture and design phase to regular patching facilitated by our Continuous Integration and Continuous Deployment pipeline. The Moogsoft Cloud web application rapidly adapts to an ever changing threat landscape.
We take the security of our corporate resources just as seriously implementing the Least Privilege and Zero Trust principles internally where able. Additionally, all personnel at Moogsoft undergo annual security awareness training and our developers undergo annual Security SDLC training.
Moogsoft’s infrastructure is hosted in the Amazon Web Services Cloud. Physical and environmental security related controls for our production infrastructure, including buildings, locks or keys used on doors, are managed by AWS.
Read about AWS Shared Responsibility Model
Web Application Security
Moogsoft processes IT data from sources such as servers, network switches, middleware, application error logs, and the like. Although Moogsoft does not require any non-IT data, any IT telemetry is considered confidential from an IT security perspective. As such, Moogsoft treats all data as sensitive and has put the required controls in place to keep all data fully protected.
Data at Rest
Data at rest is encrypted using AWS KMS and uses AES-256 encryption.
Data in Transit
Data in Transit is protected with TLS 1.2 and above. Cipher suites in use are monitored and updated regularly.
SSO
Moogsoft supports SSO authentication using the OIDC protocol.
Vulnerability Management
Moogsoft scans all resources continuously. The Moogsoft Security team partners with Moogsoft Engineering to track, prioritize, and remediate vulnerabilities in a timely manner.
Penetration Testing
Moogsoft engages with a third party firm to perform an executive penetration test of our systems every year.
BugBounty Program
Moogsoft is continuously tested via our BugBounty Program. This program is managed via HackerOne
Compliance
SOC2
Available upon request
Cloud Security Alliance STAR Level One
CAIQ available via CSA STAR Registry
GDPR
We adhere to GDPR requirements where applicable
Contact Us
For any questions, please reach out to the Moogsoft Security team
[email protected]