Third Party Index

Snapshot 25054

Document
Security page
URL
https://quaderno.io/legal/security/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
166839 bytes
SHA-256 (raw)
4e853a732d7ef60b614f5b3af8767e046736b78209e4b2ac692fc3f5f7a0346e
SHA-256 (normalized text)
060e5f526647459f8b2feb3b66b6e2258c256624469c13992c86abd6a7d0ae39

Normalized text

Scripts and page chrome removed; this is what change detection compares.

We take security and privacy seriously, adhering to enterprise-level security standards that keep your customer data protected.
Security team
We have a globally distributed infrastructure and security team on call 24/7. Our team is constantly monitoring security notifications from all 3rd party software libraries and if identified, we immediately apply any relevant security patches as soon as they are released.
Infrastructure
All of Quaderno’s application and data infrastructure is hosted on DigitalOcean, a highly scalable cloud computing platform with end-to-end security and privacy features built-in.
For more specific details regarding DigitalOcean security, please refer to https://www.digitalocean.com/legal.
Application
Through the use of automated and manual analysis, as well as constant security review of 3rd party libraries, we ensure to the best of our abilities that we are delivering products that are free from security defects. All Quaderno web application communications support TLS v1.2.
Additionally, we support a number of security-focused features to help keep your data safe:
access to the information stored within Quaderno’s servers is restricted to a limited number of Quaderno employees who can access the information only in specific and limited circumstances and are bound by confidentiality.
Quaderno’s servers are protected by (1) firewalls establishing a barrier between Our trusted, secure internal network and the Internet and (2) IP restrictions, limiting access to whitelisted IP addresses.
we use TLS v1.2 to encrypt all data-in-transit for all internal and external endpoints, providing secure transfer of data to prevent wiretapping and man-in-the-middle attacks.
public access to databases and developer endpoints are restricted with passwords and API credentials.
Engineering and operational practices
We design all services with high availability in mind. Our goal is to deliver 99.99% uptime across all our products. In order to achieve this goal, we follow a number of engineering best practices:
Immutable infrastructure - We don’t make changes to live code or running servers in production. Where applicable, we treat both our software and our infrastructure configuration as code. This means all changes go through a formal code review, automated testing, and automated deployment process.
Continuous integration and delivery - We are using continuous integration and deployment automation and configuration management tools to build, test and deploy code multiple times a day.
Incident response - Our dedicated infrastructure and security team is on a rotating on-call schedule to respond to any security or availability incidents immediately.
Reporting an issue
Our bug bounty program is temporarily closed. Thanks for your interest.