Third Party Index

Snapshot 45613

Document
Security page
URL
https://cerebrium.ai/docs/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
319533 bytes
SHA-256 (raw)
e454999a67bb9d986a046515d18ff00e3cfa8f4d1030be10801e82b9285cb17d
SHA-256 (normalized text)
1c44af4956cbf7e8efb17d0563b75c0f3bb1193c68a0e0f3c68c1a3f50a16dfa

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to main content
Cerebrium is SOC 2 Type I, HIPAA-compliant, GDPR and ISO compliant, enforcing strict security standards and protocols. Compliance is continually monitored through Vanta and a dedicated team. Visit the trust center for compliance reports, or contact [email protected] for additional information.
​
Infrastructure Security
Cerebrium frequently performs vulnerability scans, with remediation following the incident response plan timelines.
Cerebrium conducts annual business continuity and security incident exercises as required for SOC 2 compliance.
Cerebrium has daily database backups enabled.
Employee computers are frequently monitored via the Vanta agent.
Multi-Factor Authentication (MFA) is enforced across all platforms relating to Cerebrium.
Cerebrium uses logging and metrics observability providers, including Datadog and BugSnag.
​
Organizational Security
Cerebrium employees are subject to a general security awareness training during their onboarding period.
Cerebrium regularly audits employee access to internal systems.
Employee computers are frequently monitored via the Vanta agent.
Multi-Factor Authentication (MFA) is enforced across all platforms relating to Cerebrium.
​
Product Security
Cerebrium enforces HTTPS for all services using TLS (SSL), including the Cerebrium Dashboard and Python package.
Cerebrium maintains access logs across all its infrastructure services.
Software dependencies are audited by GitHub’s Dependabot.
User data is encrypted at rest.
​
Internal Security Procedures
Cerebrium performs regular vulnerability scans, with remediation following incident response plan timelines.
Cerebrium regularly audits employee access to internal systems.
Cerebrium conducts annual business continuity and security incident exercises as part of SOC 2 compliance requirements.
​
Data and Privacy
Cerebrium does not use customer data to train machine learning models.
For customers on the Hobby and Standard plans, request/log data is automatically deleted after 7 and 30 days, respectively.
Cerebrium deletes customer data upon request. A purge request endpoint is available for immediate deletion.
All user data is encrypted at rest.
​
GDPR Compliance
Cerebrium supports customer obligations under the General Data Protection Regulation (GDPR).
​
Data Processing Agreements (DPA)
Cerebrium offers a standardized DPA to customers who process personal data of individuals in the EU, UK, or other jurisdictions with equivalent requirements.
The DPA covers the roles of controller and processor, the categories of data processed, security measures, sub-processors, and international data transfer safeguards.
Customers can request a DPA by contacting [email protected].
Executed DPAs and other compliance documents are also available through the trust center.
​
HIPAA Compliance
As a business associate to covered entities in the healthcare sector, Cerebrium implements the following measures to support HIPAA compliance:
​
Business Associate Agreements (BAA)
Cerebrium offers a standardized BAA to all customers who require HIPAA compliance.
The BAA outlines the responsibilities and obligations of both parties in protecting Protected Health Information (PHI).
Customers can initiate the BAA process by contacting [email protected].
​
PHI Handling and Storage
Cerebrium’s infrastructure is designed to handle PHI securely, with encryption at rest and in transit.
Cerebrium does not access, use, or disclose PHI unless explicitly required for service delivery.
Customers are responsible for de-identifying PHI before transmission to Cerebrium’s systems, if de-identification is required for their use case.
​
Access Controls
Strict access controls are in place to ensure that only authorized personnel can access systems that may contain PHI.
Role-based access controls are used to limit access to PHI based on job responsibilities and the principle of least privilege.
​
Audit Logging
Comprehensive audit logs are maintained for all activities that could potentially involve PHI.
These logs are available to support customers’ accounting of disclosures requirements.
​
Breach Notification
Cerebrium maintains an incident response plan that includes HIPAA-compliant breach notification procedures.
Any potential breaches involving PHI are promptly investigated and reported to affected customers within required timeframes.
​
Employee Training
All Cerebrium employees undergo HIPAA awareness training as part of their onboarding process.
Regular refresher training is conducted to ensure ongoing HIPAA compliance.
​
Risk Assessments
Cerebrium conducts regular risk assessments to identify and address potential vulnerabilities in PHI handling.
These assessments help maintain a secure environment for customer data.
​
Subcontractors
Any subcontractors who may have access to PHI are required to sign a BAA and comply with the same HIPAA requirements as Cerebrium.
​
Data Retention and Destruction
Cerebrium adheres to HIPAA-compliant data retention policies.
Secure data destruction processes are in place for when PHI needs to be deleted or when a customer relationship ends.
​
Compliance Monitoring
HIPAA compliance measures are continuously monitored and updated to align with changes in regulations and best practices.
For more information on HIPAA compliance or specific compliance needs, contact the compliance team at [email protected].