Third Party Index

Snapshot 22291

Document
Security page
URL
https://helpwise.io/security/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
17790 bytes
SHA-256 (raw)
26d356a66fd31937beca5b341f80ecb20ee6bd480c49ba13183259f0f2ad2835
SHA-256 (normalized text)
41c6770fcba13c9ae290d08d579162737bad7a80aaf55101d20bb5f06e3e5bb2

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Home
About Us
What Is Shared Inbox?
How It Works?
GDPR Compliance
Privacy Policy
Terms
Security
Hall of Fame
On This Page
SECURITY
1. We protect your data
At Helpwise, security is our absolute highest priority. In the spirit of openness and transparency, here are some of the security measures we take to protect and defend the Helpwise platform.
2. Your messages never leaves our servers
We distinguish between data about your users and data about you, yourself. While, for example, your billing information is shared with Stripe, and your profile is accessible to us in our help desk software, any data about your messages are never shared with any external providers, and never leaves our server cluster hosted with Amazon Web Services unless explicitly requested.
3. Encrypting data in transit
Whenever your data is in transit between you (or your users) and us, everything is encrypted, and sent using HTTPS.
During a user agent's (typically a web browser) first site visit, Helpwise sends a Strict Transport Security Header (HSTS) to the user agent that ensures that all future requests should be made via HTTPS even if a link to Helpwise is specified as HTTP. Additionally, we use HSTS preload, guaranteeing that requests are never - not even the very first - made over a non-encrypted connection. Cookies are also set with a secure flag.
4. Encrypting data at rest
Any files which you upload to us are stored and are encrypted at rest. Email content is encrypted at rest. Metadata about messages, conversations, contacts, etc. (all stored in Amazon RDS) are encrypted at rest — they are active in our database. Our backups of your data are encrypted.
5. Hosted on Amazon Web Services
Helpwise is hosted on Amazon Web Services. Our database is managed by Amazon RDS, ensuring redundancy, high availability and trustworthy automated, encrypted backups.
Amazon Web Services is certified for a growing number of compliance standards and controls, and undergoes several independent third party audits to test for data safety, privacy, and security. Read more about the specific certifications on the AWS compliance page.
6. Concurrency and rate limiting
We employ several layers to protect against abuse and DoS attacks, such as concurrency limiting (limits number of active requests) and rate limiting (limits number of requests over time). Our servers gracefully queue requests when under high load, and handles them at a safe pace.
7. Organizational Practices
We operate under the principle of least privilege: Employees are assigned the lowest level of access that allows them to do their work.
Two-factor authentication is enforced in all sensitive systems.
All employees are required to use approved password managers (like Lastpass or 1Password) to generate and store strong passwords that are never reused.
All employees are required to encrypt local hard drives and enable screen locking for device security.
All access to application admin functionalities is restricted to a small subset of Helpwise staff.
We never store customer data on personal devices (like laptops).
8. Development practices
All code changes are thoroughly tested through our Continuous Integration software.
All code changes is tested in a staging environment before deploying to production.
We use automatic security vulnerability detection tools to alert us when our dependencies have known security issues. We are aggressive about applying patches and deploying quickly.
We use several tools and services to automatically monitor uptime and site availability. Key employees receive automatic email and SMS notifications in the case of downtime or emergencies.
Logs are permanently deleted after 14 days.
9. Penetration Testing
On top of our development-related continuous testing, we also conduct periodic third-party manual penetration testing of both our application and infrastructure. You can request a copy of our latest report at dev@helpwise.io.
10. Regularly-updated infrastructure
Our software infrastructure is updated regularly with the latest security patches. Our products run on a dedicated network which is locked down with firewalls and carefully monitored. While perfect security is a moving target, we work with security researchers to keep up with the state-of-the-art in web security.
11. We protect your billing information
All credit card transactions are processed via Stripe using secure encryption—the same level of encryption used by leading banks. Card information is transmitted, stored, and processed securely on a PCI-Compliant network.
12. Have a concern? Need to report an incident?
Have you noticed abuse, misuse, an exploit, or experienced an incident with your account? Send urgent or sensitive reports directly to dev@helpwise.io. We'll get back to you as soon as we can, usually within 24 hours. Please follow up if you don't hear back. For requests that aren't urgent or sensitive: submit a support request.
Keeping customer data safe and secure is a huge responsibility and a top priority. We work hard to protect our customers from the latest threats. Your input and feedback on our security is always appreciated.
13. Additional Policies
Access Onboarding and Termination Policy
Application Security Policy
Asset Inventory Management Policy
Availability Policy
Business Continuity Policy
Code of Conduct Policy
Confidentiality Policy
Data Center Policy
Data Classification Policy
Disaster Recovery Policy
Encryption Policy
Information Security Policy
Log Management Policy
Password Management Policy
Remote Access Policy
Removable Media and Cloud Storage Policy
Responsible Disclosure Policy
Risk Assessment Policy
Security Incident Response Policy
Software Development Lifecycle Policy (SDLCP)
System Change Policy
Vendor Management Policy
Workstation Policy
Last updated: 28th August 2023