Third Party Index

Snapshot 39946

Document
Security page
URL
https://www.teramind.co/wp-content/uploads/2024/06/Teramind-Platform-Security.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
1673434 bytes
SHA-256 (raw)
53074a6c4a92812d794603c722df6a30d646c3e488961bf5cc9ff6f931284392
SHA-256 (normalized text)
4015b221f3da8a24f2ee2bd5dba23226e894f7389050a16581425b99f5df03ed

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Insider Risk Management,
Employee Monitoring &
Productivity Optimization
Through Endpoint Telemetry
About
Since 2014, over 10,000 organizations
around the world have trusted Teramind to
provide insider threat management, data loss
prevention, and business process optimization
through behavioral user data. By harnessing
behavior analytics, our award-winning
platform has helped enterprises in finance,
retail, manufacturing, energy, technology,
healthcare, and government optimize their
workforce and protect their businesses.

                                                1
Platform Security
Teramind is committed to protecting its platform and the
data it collects.

         Certifications and Frameworks

Teramind follows the most rigorous security controls and frameworks, and is certified by
Bureau Veritas for its achievement in meeting international security standards.

   ISO 27001:2013 Certification      ISMS Framework                     NIST Frameworks

   ISO 27001 is the international    Information Security               The National Institute of
   standard for best practices in    Management System (ISMS)           Standards and Technology
   information security.             best practices ensure the          (NIST) Cybersecurity
   Organizations with ISO            confidentiality, availability,     Framework provides strict
   certification, like Teramind,     and integrity of all of our IT     guidance for private sector
   have proven through audit a       assets. Nodes and repositories     organizations in the US on how
   demonstrated, ongoing             where data is hosted and           to best prevent, detect, and
   commitment to the highest         stored are sensibly protected      respond to cyberattacks.
   standards in data security and    from threats and                   Teramind applies this
   privacy.                          vulnerabilities.                   framework to customer data
                                                                        processing and internal
                                                                        business processes.

          Data Storage

Teramind uses the latest and most secure data storage practices to ensure customer data
is stored safely and securely while still being accessible.

   256-bit AES encryption for all    TLS with a 4-key system and        Adherence to GDPR’s Right to
   Teramind data, including          Active Validation for all Active   Erasure for EU citizens’
   customer data, at-rest.           Directory LDAP connections.        personal data.

   Encryption in motion to protect   Active Directory integration       Deletion upon customer
   data being transmitted from       capability.                        request policies.
   network to public nodes.
                                     Role-based access control          Session recordings stored for
   SSL with 4-key system and         (RBAC) options and features.       a period of six months, after
   Active Validation for all HTTPS                                      which it is deleted.
   interactions.                     Multi-factor authentication
                                     (MFA)/Two-factor                   Programmatic deletion of
   256-bit AES end-to-end            authentication (2FA) options.      session recordings.
   encryption for all endpoint –
   server communications.

         Secure Deployment

The data centers and storage used by Teramind for its On-Premise and Cloud deployments
feature rigorous controls and compliance, offering uncompromising security.

                                                                                                        2
         Data Centers

Teramind Cloud deployments are hosted on multi-homed Tier-3 data centers. Tier-3 data
centers are designed to handle large businesses and mission critical applications, and meet
the strictest reliability requirements that provide the following:

  PCI accreditation.              99.982% uptime                   N+1 Fault Tolerant, minimum
                                                                   72-hour power outage
  Multi-ISO certification.        PS 951 certification.            protection.

  Maximum 1.6 hours of            Multi-node architecture that
  downtime per year.              ensures 99.82% SLA.

         Platform Security Measures

Teramind’s security extends beyond its certifications and frameworks to include other
company-wide measures that protect the platform, our customers, and their data.

  Red Teaming & Penetration       Redundancy & Backup              RTO & RPO
  Testing
                                  Failover measures ensure         Teramind sets the industry
  Regular ethical hacking and     server and deployment health     standard for fastest recovery
  cyberattack simulations         while daily back-ups keep data   time objective (RTO) and
  identify vulnerabilities and    secure.                          recovery point objective (RPO)
  security gaps, test incident                                     for both its systems and
  response, and asses potential                                    customer support.
  risk.

         Company Security Measures

Our top-down security approach ensures not only the security of customer data but also
the security of our own business processes.

  HR Security                     Network Security                 User Activity Monitoring

  Background checks, contracts    Intrusion detection, port        As an endpoint monitoring
  & NDAs, role-based access       blocking, DDoS attack            provider, we utilize our own
  controls as well as industry-   response, and FTP/SSH            product to monitor data usage
  leading and proprietary         sessions provide additional      and activity.
  product development controls    security to our network.
  bolster staff-level data
  security.

                                                                                                 3
Request
Your Custom
Demo Now

 Get Demo