Third Party Index

Snapshot 36014

Document
Security page
URL
https://www.bolddesk.com/legal/security
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
912953 bytes
SHA-256 (raw)
bd0ae1c55826381c508b763bfc63796218e6d78fa7c42cdcefd92b353b4f2589
SHA-256 (normalized text)
3d8a788574b4852d6bc55bbf7b639c9645baf46d56f594e333391fa2fb503ff9

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security and Compliance
At BoldDesk, we do everything to make sure your data is always safe with us. You probably came here because you have questions, so let’s answer the important ones.
Home
Privacy Policy
Terms Of Use
Affiliate Program Terms
and Conditions
SLA
NIST 800-53 Overview
SOC 2® Overview
Request Form
Security Policy
Cookie Policy
DPA
GDPR Overview
HIPAA Overview
Modern Slavery Statement
Sub-processors
Ethics Policy
Responsible Disclosure
AI Chatbot Disclaimer
AI Disclaimer
TX-RAMP Level 2 Certification
SOC 2 Type 2
Our SOC 2 Type 2 certification verifies that BoldDesk has successfully completed a thorough audit, ensuring that our security policies and controls consistently meet the highest industry standards when it comes to keeping data safe and secret.
SOC2 Overview
HIPAA Compliance
BoldDesk helps you stay compliant with the U.S. Health Insurance Portability and Accountability Act (HIPAA). We can securely handle and store protected health information (PHI) for healthcare organizations and other regulated entities.
To use BoldDesk in a HIPAA-compliant way, sign a Business Associate Agreement (BAA) with us. From there, we’ll make sure your support data is protected and compliant.
HIPAA Overview
Sign Your BAA
GDPR Compliant
As a company, we take data privacy very seriously and maintain GDPR compliance with many customers in Europe.
Contact sales for more information
Datacenter Security
All our platform infrastructure is hosted on Google Cloud Platform (GCP) and Microsoft Azure within virtual private clouds (VPC) we configure and manage to safeguard against unauthorized network requests. GCP and Azure are deeply committed to securing the underlying infrastructure we build on, and they are continuously expanding their compliance programs.
Google Cloud Platform Data and Security
Microsoft Azure Data and Security
Software Security
Our application runs on the latest stable version of the Microsoft .NET Framework. We reduce the attack surface by isolating our processes with containerized microservice architecture. Our application is also automated with a real-time static analyzer tool that does extensive computation and ensures the security of our source code.
PCI DSS Certification
BoldDesk uses Stripe, a payment processor compliant with PCI standards, to encrypt and store credit card details. Further details on Stripe’s dedication to security and regulation adherence are available here. By integrating Stripe’s direct JavaScript integration, we ensure that your credit card details are never transmitted to BoldDesk servers. For more details, read Security at Stripe.
Encrypted Transmission
All user data is transported securely, encrypted in transit and encrypted at rest. Encrypting your data provides an additional layer of protection against events such as unauthorized modification and man-in-the-middle attacks. We use 256-bit SSL/TLS 1.2 encryption and industry-standard AES-256 algorithms.
Vulnerability Scans
BoldDesk uses security tools to continuously scan for vulnerabilities. Additionally, vulnerabilities in third-party libraries and tools are monitored and software is patched or updated promptly when new issues are reported.
Penetration Testing
BoldDesk undergoes regular penetration testing by our in-house security experts and development team. A yearly detailed penetration test is performed by third-party security experts to confirm the security of our products and environment.
Privacy and GDPR
BoldDesk recognizes that protecting privacy requires a comprehensive security program. BoldDesk is fully GDPR-compliant, and we handle our customers' personal data with great care and respect, as outlined in our terms of service and privacy policy.
Monitoring and Alerting
Our application and the underlying infrastructure components are actively monitored 24/7. Our engineers are immediately notified in case of an outage. You can view our historical product reliability details on the status page.
Backup and Availability
To maximize availability, our systems automatically replicate your data across multiple locations in real time. Data is also continuously backed up to ensure that we can restore access to your data and the service in the unlikely event that all data replicas fail simultaneously. Our monitoring system alerts us to any problems, and we have staff on call at all times to handle any unexpected incidents.
Uptime
BoldDesk has a 99.9% uptime or higher. To check the system status at any time, go to the status page. If our systems require maintenance or a brief outage, clients will be notified in advance
For more security details, please refer to our Security Management Report.
Enterprise-Grade Security and Privacy
To protect your customers’ data, security systems control access to your entire organization and secure your data at multiple levels. Encryption, audit logs, IP restrictions, and SSO are features that can help you protect your data and restrict access to only authorized users.
Single Sign-On
Single sign-on with BoldDesk allows users to log in and access their help desk account with a single set of credentials by using systems such as Office 365, OAuth 2.0, and OpenID.
IP Restrictions
IP restrictions allow you to limit the IP addresses from which your organization can access the help desk.
Password Policies
Create password policies to enforce secure, strong passwords; frequent password rotation; and password expiration to fit your security standards and policies.
Allowlist or Blocklist Senders
Accept or reject emails received from specific senders and domains. Emails on the blocklist are blocked and are not routed to spam.
DKIM for Email
DKIM signatures notify the recipient that an email is sent from an authorized domain.
Audit Logs
Audit logs contain information about specific events or operations, such as access, change details, who performed an action, and so on.
Questions
If you believe you have found a security vulnerability in BoldDesk, please let us know right away.
You can find more information on reporting a vulnerability here.