Third Party Index

Snapshot 42380

Document
Security page
URL
https://localiq.com/legal/security-policy/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
browser
Size
303546 bytes
SHA-256 (raw)
ea54b7cf46fd85c5dc8d39e3e74992c2e942b22090d3b92781a64eb242ec30dd
SHA-256 (normalized text)
d3068fa0a762d19a12785463def71f7e8ffd5f9856783674172729169d0c98ca

Normalized text

Scripts and page chrome removed; this is what change detection compares.

LocaliQ Security Policy
1. SOC2 Certification
2. Access Controls and Encryption
3. Device and Platform Security
4. Education and Training
5. Incident Response
6. Application Protection
7. Availability & Disaster Recovery
8. HIPAA Security Audit
9. PCI Compliance
LocaliQ Security Policy
LocaliQ Security Policy
1. SOC2 Certification
2. Access Controls and Encryption
3. Device and Platform Security
4. Education and Training
5. Incident Response
6. Application Protection
7. Availability & Disaster Recovery
8. HIPAA Security Audit
9. PCI Compliance
LocaliQ Security Policy
Last Updated: October 3, 2024
1. SOC2 Certification
SOC2 Certification
An independent third-party auditor has successfully completed an examination of the design and operating effectiveness of the System and Organization Controls (SOC) relevant to the security, confidentiality, availability, and privacy trust criteria of the LocaliQ solutions and marketing platform. The audit determined that LocaliQ has adequate controls in place to protect customers and sensitive data and was performed in accordance with the AICPA (American Institute of Certified Public Accountants) attestation standards.
These practices include encryption of data in transit and at rest, security monitoring and logging, enterprise-class endpoint detection and response solutions, continuous integration and deployment, application security testing and scans, incident response, security awareness training, and secure development lifecycle.
Our security program includes:
Use of Security Orchestration Automation & Response (SOAR) technology to automate security monitoring, alerting, and response capabilities.
Security Information & Event Management (SIEM) platform
Automated, continuous vulnerability scanning using threat intelligence to identify high-risk exploitable vulnerabilities.
Background checks for all personnel.
Third-party pen testing to identify security risks.
2. Access Controls and Encryption
Multi-Factor Authentication (MFA), VPN access, and strong password controls are required for remote administrative access to systems.
Access Control Lists (ACLs) prevent unauthorized network access.
Firewalls are configured to deny all network connections and only allow authorized connections by default.
Customer provided credentials are securely vaulted, and encrypted at rest (AES-256) and in transit (TLS 1.2 and above)
User passwords are hashed following industry best practices and are encrypted at rest.
Role-based access controls ensure that access is restricted to authorized users.
Access requests and authorizations are logged to review, investigate, and resolve issues.
3. Device and Platform Security
Next-Gen Anti-Virus/Anti-Malware (NGAV) with behavioral threat detection.
Endpoint Detection and Response (EDR) capabilities.
Mobile Device Management (MDM) controls deployed on mobile devices.
Cloud Security Posture Management (CSPM) technology for continuous, automated cloud infrastructure monitoring for misconfigurations and risky configurations.
4. Education and Training
Mandatory security awareness training for all personnel upon hire, and on an annual basis.
Communications to all personnel on security tips and how to report suspicious or unusual activity.
Scheduled email phishing campaigns to help personnel identify suspicious emails.
Specialized training based on role, such as Security Analyst or Developer.
5. Incident Response
Up-to-date incident response plans are reviewed and updated at least annually.
Corporate Cybersecurity Incident Response Team (CIRT) provides 24x7x365 coverage to respond quickly to all types of security events.
Incident response retainers with leading breach response and law firms if needed.
6. Application Protection
Change management control and documentation.
Peer review practices of source code.
Source code Application Security Testing (SAST) scanning to detect security vulnerabilities in the code base for our most modern apps and services.
Next-gen Web Application Firewalls (WAF) for additional real-time protection to meet the most stringent PCI DSS requirements as a Level 1 merchant.
Agile practices incorporating security updates into releases.
7. Availability & Disaster Recovery
Use of geographic diverse data centers and leading cloud providers (Amazon Web Services & Google Cloud Platform).
Data centers use N+1 UPS and power systems and alternate cooling system.
8. HIPAA Security Audit
HIPAA Security Audit
LocaliQ is a Business Associate that provides digital marketing products and services to healthcare organizations that collect their customers' protected health information (PHI). An independent security and compliance auditor reviewed LocaliQ’s controls and confirmed that LocaliQ follows the requirements for Business Associates under the Health Insurance Portability and Accountability Act (HIPAA) and related regulations for protecting PHI.
Stringent Security Standards: LocaliQ meets stringent HIPAA security standards. Our robust security protocols safeguard client data, ensuring its integrity and confidentiality.
Access Controls: Access controls refer to the technical policies and procedures that allow authorized individuals or software programs to access electronic protected health information (e-PHI).
Vendor Security Reviews: We conduct thorough security assessments of our subcontractors who provide services to LocaliQ for our HIPAA-covered entity clients. This includes areas such as call recording and chat functionalities.
Platform Security: Beyond data protection, we limit access to your HIPAA account information to the minimum necessary for platform functionality. Only a select group of HIPAA trained representatives have authorization to access HIPAA regulated business accounts.
9. PCI Compliance
LocaliQ has been certified by a Qualified Qualified Security Assessor (QSA) company which is an independent security organization that the PCI Security Standards Council has qualified to validate an entity’s adherence to PCI DSS. The assessment performed by the third party QSA determined that LocaliQ complies with the Payment Card Industry Data Security Standard, which refers to a set of security standards to prevent fraud, protect customer payment card information and maintain a secure environment. It involves requirements such as installing security patches, managing firewalls, updating antivirus software and assigning unique IDs to each person with computer access. LocaliQ never stores your payment card number.