Snapshot 42380
Normalized text
Scripts and page chrome removed; this is what change detection compares.
LocaliQ Security Policy 1. SOC2 Certification 2. Access Controls and Encryption 3. Device and Platform Security 4. Education and Training 5. Incident Response 6. Application Protection 7. Availability & Disaster Recovery 8. HIPAA Security Audit 9. PCI Compliance LocaliQ Security Policy LocaliQ Security Policy 1. SOC2 Certification 2. Access Controls and Encryption 3. Device and Platform Security 4. Education and Training 5. Incident Response 6. Application Protection 7. Availability & Disaster Recovery 8. HIPAA Security Audit 9. PCI Compliance LocaliQ Security Policy Last Updated: October 3, 2024 1. SOC2 Certification SOC2 Certification An independent third-party auditor has successfully completed an examination of the design and operating effectiveness of the System and Organization Controls (SOC) relevant to the security, confidentiality, availability, and privacy trust criteria of the LocaliQ solutions and marketing platform. The audit determined that LocaliQ has adequate controls in place to protect customers and sensitive data and was performed in accordance with the AICPA (American Institute of Certified Public Accountants) attestation standards. These practices include encryption of data in transit and at rest, security monitoring and logging, enterprise-class endpoint detection and response solutions, continuous integration and deployment, application security testing and scans, incident response, security awareness training, and secure development lifecycle. Our security program includes: Use of Security Orchestration Automation & Response (SOAR) technology to automate security monitoring, alerting, and response capabilities. Security Information & Event Management (SIEM) platform Automated, continuous vulnerability scanning using threat intelligence to identify high-risk exploitable vulnerabilities. Background checks for all personnel. Third-party pen testing to identify security risks. 2. Access Controls and Encryption Multi-Factor Authentication (MFA), VPN access, and strong password controls are required for remote administrative access to systems. Access Control Lists (ACLs) prevent unauthorized network access. Firewalls are configured to deny all network connections and only allow authorized connections by default. Customer provided credentials are securely vaulted, and encrypted at rest (AES-256) and in transit (TLS 1.2 and above) User passwords are hashed following industry best practices and are encrypted at rest. Role-based access controls ensure that access is restricted to authorized users. Access requests and authorizations are logged to review, investigate, and resolve issues. 3. Device and Platform Security Next-Gen Anti-Virus/Anti-Malware (NGAV) with behavioral threat detection. Endpoint Detection and Response (EDR) capabilities. Mobile Device Management (MDM) controls deployed on mobile devices. Cloud Security Posture Management (CSPM) technology for continuous, automated cloud infrastructure monitoring for misconfigurations and risky configurations. 4. Education and Training Mandatory security awareness training for all personnel upon hire, and on an annual basis. Communications to all personnel on security tips and how to report suspicious or unusual activity. Scheduled email phishing campaigns to help personnel identify suspicious emails. Specialized training based on role, such as Security Analyst or Developer. 5. Incident Response Up-to-date incident response plans are reviewed and updated at least annually. Corporate Cybersecurity Incident Response Team (CIRT) provides 24x7x365 coverage to respond quickly to all types of security events. Incident response retainers with leading breach response and law firms if needed. 6. Application Protection Change management control and documentation. Peer review practices of source code. Source code Application Security Testing (SAST) scanning to detect security vulnerabilities in the code base for our most modern apps and services. Next-gen Web Application Firewalls (WAF) for additional real-time protection to meet the most stringent PCI DSS requirements as a Level 1 merchant. Agile practices incorporating security updates into releases. 7. Availability & Disaster Recovery Use of geographic diverse data centers and leading cloud providers (Amazon Web Services & Google Cloud Platform). Data centers use N+1 UPS and power systems and alternate cooling system. 8. HIPAA Security Audit HIPAA Security Audit LocaliQ is a Business Associate that provides digital marketing products and services to healthcare organizations that collect their customers' protected health information (PHI). An independent security and compliance auditor reviewed LocaliQ’s controls and confirmed that LocaliQ follows the requirements for Business Associates under the Health Insurance Portability and Accountability Act (HIPAA) and related regulations for protecting PHI. Stringent Security Standards: LocaliQ meets stringent HIPAA security standards. Our robust security protocols safeguard client data, ensuring its integrity and confidentiality. Access Controls: Access controls refer to the technical policies and procedures that allow authorized individuals or software programs to access electronic protected health information (e-PHI). Vendor Security Reviews: We conduct thorough security assessments of our subcontractors who provide services to LocaliQ for our HIPAA-covered entity clients. This includes areas such as call recording and chat functionalities. Platform Security: Beyond data protection, we limit access to your HIPAA account information to the minimum necessary for platform functionality. Only a select group of HIPAA trained representatives have authorization to access HIPAA regulated business accounts. 9. PCI Compliance LocaliQ has been certified by a Qualified Qualified Security Assessor (QSA) company which is an independent security organization that the PCI Security Standards Council has qualified to validate an entity’s adherence to PCI DSS. The assessment performed by the third party QSA determined that LocaliQ complies with the Payment Card Industry Data Security Standard, which refers to a set of security standards to prevent fraud, protect customer payment card information and maintain a secure environment. It involves requirements such as installing security patches, managing firewalls, updating antivirus software and assigning unique IDs to each person with computer access. LocaliQ never stores your payment card number.