Snapshot 39969
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Docs powered by Archbee Software Specifications Security & IT Standards 24 min To support your security and IT due diligence processes, weโve summarized our current protocols, certifications, and controls below. These standards apply across all client environments supported by the ClearSquare and Domo infrastructure. ๐ Data Encryption in Transit Yes, all data in transit is encrypted using industry-standard TLS protocols. TLS Versions Supported: TLS 1.2, TLS 1.3 Cipher Suites: Common secure suites include ECDHE-RSA-AES256-GCM-SHA384 and ECDHE-ECDSA-AES128-GCM-SHA256 Access URL: Provided at time of onboarding for each clientโs portal instance ๐งฑ Data Separation Client data is logically separated and securely isolated: Database: Each client has a logically isolated schema on DigitalOcean Managed Databases Network: Hosted within dedicated VPC/subnet Files: Stored in client-specific AWS S3 buckets with strict IAM-based access controls Application Layer: Shared, with strict tenant-based access controls and logical separation ๐ก๏ธ Infrastructure Hardening Our infrastructure is hardened to meet modern protection standards: Malware & Patch Management: Automated and managed by DigitalOcean and AWS Firewall: Network-level firewalls with "deny-all by default" and explicit port rules (HTTPS only) Security Practices: No unnecessary components or services Restricted system tools Regular vulnerability scans and patching Principle of least privilege enforced ๐พ Backup Security Encryption: All backups are encrypted at rest with AES-256 DigitalOcean Managed DBs: Encrypted automatic backups AWS S3: Encrypted with SSE-S3 or SSE-KMS Access: Controlled by role-based permissions and access logs ๐ System Management Standards We align our system management with ITIL and ISO 20000 principles: CI/CD workflows and automated deployment pipelines Provider-level incident management and rollback support ๐ Information Security Compliance Infrastructure partners (DigitalOcean, AWS, GitHub) hold certifications including ISO/IEC 27001, SOC 2 Type II, and more: DigitalOcean Trust Center AWS Compliance GitHub Security ๐ Activity & Privileged Access Monitoring Admin Activity: Logged using native tools (e.g., CloudTrail, GuardDuty, GitHub logs) Privileged Access: No shared accounts, MFA enforced, access is logged and permission-controlled Data Export Controls: USB, email, or unauthorized exports are restricted ๐ Security Event Logging Threat Monitoring: AWS GuardDuty DigitalOcean system logs GitHub dependency & secret scanning Detection & Response: Alerts for unusual behavior, brute force attempts, and suspicious activity โ๏ธ Hosting Providers DigitalOcean (App Platform, Managed DBs) AWS (S3 file storage) Both providers are ISO 27001 certified and undergo SOC 2 Type II audits ๐งช Penetration Testing & SDLC Security Annual third-party network penetration tests Secure Software Development Lifecycle includes: Code reviews SAST & DAST tools CI/CD pipelines with secret scanning ๐ Supplier & Dependency Security We only use vendors that meet industry-standard SDLC security practices Automated dependency scanning (e.g., GitHub Dependabot) Secure build pipelines with encrypted secrets ๐ Pre-Deployment Reviews All deployments undergo: Code reviews for best practices Dependency vulnerability scanning Manual and automated QA testing ๐ Data Encryption at Rest All data is encrypted using AES-256 encryption: App Platform: Encrypted disk volumes Managed DBs: Encrypted database storage and backups AWS S3: Encrypted with SSE-S3 or SSE-KMS ๐ Key Management AWS KMS for server-side encryption GitHub Encrypted Secrets for application secrets Access is tightly scoped and rotated regularly (quarterly or automated where supported) ๐งโ๐ผ Admin Controls & Audit Logs Role Management: Multi-tiered access controls (Super Admins, Admins, Users) Activity Logging: User logins/logouts Permission changes Page/workspace changes Logs exportable as Domo datasets or in XLS/CSV ๐ง Data Loss Prevention (DLP) Amazon GuardDuty for S3 threat detection IAM policies and private buckets enforce access restrictions ๐ SSO & Password Security SSO Support: SAML 2.0 via providers like Okta, Azure AD, Salesforce, etc. Password Hashing: bcrypt with automatic salting ๐ Business Continuity & Disaster Recovery A formal response will be provided upon request by our operations team. ๐ Security with Hosting Providers Shared responsibility model DigitalOcean: Firewalls, automated patching AWS: GuardDuty, IAM, encryption GitHub: Private repos, MFA, encrypted secrets ๐ Vulnerability & Patch Management Scanning cadence: Continuous (application), automated (infrastructure) Patch SLAs: Critical: 24โ48 hrs High: 2โ3 business days Medium: 4โ5 business days ๐ฅ Firewall Rules Monthly reviews Deny-all default, only HTTPS opened IAM-controlled S3 and CI/CD access via secure HTTPS ๐ก Intrusion Detection (IDS/IPS) GuardDuty serves as our IDS/IPS ML-powered anomaly detection across VPC, IAM, S3 No agent installation required ๐งฐ OS & Console Security OS Hardening: Fully managed by DigitalOcean Client Devices: Access is enforced via MFA and scoped permissions Admin Consoles: Hardened by provider defaults (e.g., timeouts, MFA, access logs) ๐งฌ Antivirus / Malware Protection All systems have real-time malware protection, managed by infrastructure providers, with routine updates and monitoring. Let us know if youโd like supporting documents (e.g., certifications, penetration test summaries) or would like to schedule a security review call. Contact: [email protected] Portal Site: https://clearsquare.co Updated 21 Jul 2025 PREVIOUS Software Specifications NEXT What Features Can You Access? Docs powered by Archbee Docs powered by Archbee