Third Party Index

Snapshot 21238

Document
Security page
URL
https://www.twinit.com/security
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
1008028 bytes
SHA-256 (raw)
6188addc13de829a09d916d7b768edc5f95f3cc543407bf45b819f5a8c0efb37
SHA-256 (normalized text)
62f16053994f2bc6c5639441069417e9bc844fe47a54079ebc582ee70d6e0280

Normalized text

Scripts and page chrome removed; this is what change detection compares.

top of page
Security
Twinit Trust Centre
Security
Security of customer data is of the utmost importance to Twinit and to achieve that a comprehensive set of controls, monitors and processes have been put in place to ensure that security.
Platform
Encryption: All data on the Twinit Platform is encrypted at rest with at least AES256 and in transit with TLS 1.2 or 1.3.
​
WAF: Access to the Twinit Platform is via a Web Application Firewall (WAF) which features both standard rules-based and AI determined threat blocking.
Architecture: The Twinit Platform is based in the AWS public cloud and fully leverages all the security benefits that such an environment offers. This includes measures to separate the various services comprising the platform, control traffic flows between them and from external sources.
​
Patching: All systems are monitored continually for patch currency and updated with the latest releases as soon as they are made available.
​
High Availability: All systems are configured for maximum resiliency. This ensures customer data will always be available when it’s needed.
​
Backup and Recovery: All data is automatically backed-up on a continual basis. These backups are then stored for a minimum of once month, some for much longer.
​
Intrusion Detection: This is applied to both the incoming traffic to the platform and to the cloud accounts running the platform.
​
CSPM: All cloud accounts are continually evaluated for security posture and configuration errors.
​
SIEM: All platform security events are logged to a central SIEM for later analysis and realtime alerting.
Program
Architecture: The Twinit platform is designed from the ground-up to be secure. It is a multi-tenant, stateless, micro-service based architecture with each individual service requiring authorisation from the Passport Service to which users are authenticated. Authentication uses SAML 2.0 which, together with OAuth 2.0, can be directed to use a third party IdP. All data is scoped to “namespaces”, which enforce isolation between tenants and applications. Each service exposes REST APIs which use JWT-based authentication. Authorisation uses a granular permission model (IRNs, CRUD actions, per-namespace). An API gateway is the sole external entry point. Client-defined scripts execute in sandboxed, network-restricted Kubernetes pods. PII is minimised. Every write operation emits a structured audit event.
​
SAST: All code that goes into the Twinit platform is thoroughly tested for coding vulnerabilities using the latest AI enhanced testing techniques. Thus issues are identified very early in the software lifecycle and remediated long before they get into the deployed platform.
​
SCA: All third-party code from libraries and opensource projects used is additionally scanned for currency and known vulnerabilities. If any third-party code is found to be out of date or having known issues then it is immediately updated thus eliminating the risk of supply chain attacks.
​
Secrets detection:The Twinit platform code base is additionally scanned for secrets such as usernames, passwords etc that may have been inadvertently added to the platform. This is performed on a per-commit basis to prevent secrets ever being leaked in this way.
Process
Incident Response: In the event of a security incident, it is handled inline with the Twinit Incident Response process. Incidents are first triaged from Critical to Low depending on the nature of the incident. An incident team is then assembled and issues are remediated within defined timescales for each severity level.
​
Vulnerability Handling Process: Vulnerabilities discovered in the platform are triaged and fixed in line with the Vulnerability Handling Process. Once remediated and tested the fix is then made available to customers within defined timescales.
​
External Penetration testing: Penetration tests performed by third party consultancies are commissioned on a regular basis. This tests the platform and associated defences in totality. Third party consultancies bring additional expertise and an adversarial approach to security testing. s.
​
Regulatory and Compliance
Compliance
Twinit takes compliance with applicable legislation is all territories in which it operates very seriously. To this end it is compliant with these and other legal requirements:
​
GDPR (EU General Data Protection Regulation)
​
DPDP (Digital Personal Data Protection Act, 2023)
​
Cert-In (Indian Computer Emergency Response Team)
​
EU AI Act (European Union Artificial Intelligence Act)
Certifications
Twinit is proud to be the holder of the following certifications:
​
​
bottom of page