Third Party Index

Snapshot 62716

Document
Security page
URL
https://www.saleschoice.com/security/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
81936 bytes
SHA-256 (raw)
fac5ddedc07258e4664a1821cb21892950fcbd5228ea85efa848d73211a47294
SHA-256 (normalized text)
d84d8b1c269b3d1a1997a7959675b84f8c8c396f336cbd3fd5792f9fac3e6ce9

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Close Search
Security & Data Protection
At SalesChoice, safeguarding enterprise data, predictive AI models, and user privacy is foundational to everything we build. Our security framework is designed to meet strict industry standards, ensuring your data remains protected, confidential, and highly available across our SalesInsights and MoodInsights platforms.
Our Compliance & Governance Posture
SOC 2 Alignment: Built and maintained in accordance with the AICPA SOC 2 Trust Services Criteria (Security, Confidentiality, and Availability).
Continuous Monitoring: We utilize Vanta for 24/7 automated control monitoring and compliance verification across our cloud infrastructure, code repositories, and operational workflows.
Independent Auditing: Regular internal assessments and third-party penetration testing validate our security defenses against evolving threat vectors.
1. Cloud Infrastructure & Network Defense
SalesChoice is hosted natively within Amazon Web Services (AWS) enterprise data center infrastructure.
Virtual Private Cloud (VPC) Isolation: All application workloads operate within isolated VPC environments, partitioned across public, application, and database subnets.
Virtual Firewalls & Network ACLs: Access to internal systems is restricted via AWS Security Groups enforcing strict inbound and outbound traffic rules. Direct public internet access to administrative ports (e.g., SSH Port 22) or internal database ports is strictly prohibited.
High Availability & Redundancy: Production workloads leverage multi-Availability Zone (AZ) deployments to ensure service resilience and automatic fault tolerance.
2. Data Encryption & Privacy Controls
Encryption Standards
Data in Transit: All traffic between user browsers, API endpoints, and SalesChoice infrastructure is encrypted in transit using TLS 1.2 or higher with modern cipher suites. Unencrypted HTTP traffic is automatically upgraded to HTTPS.
Data at Rest: All customer databases, data stores, system logs, and cloud storage buckets (AWS S3) are encrypted at rest using industry-standard AES-256 encryption.
Privacy by Design & PII Protection
Data Isolation: Customer data is logically segregated within multi-tenant databases to prevent cross-tenant data access.
AI Model Security: Customer datasets processed by SalesInsights and MoodInsights are sanitized and anonymized within AI/ML data pipelines to protect Personally Identifiable Information (PII).
No Unsanctioned Data Sharing: SalesChoice never sells customer data or shares proprietary client analytics with third parties.
3. Access Control & Identity Management
Principle of Least Privilege: System and data access rights are granted strictly on a role-based, need-to-know basis.
Multi-Factor Authentication (MFA): MFA is strictly mandated across all corporate, developer, and cloud administrative accounts (Google Workspace, AWS, GitHub, Vanta).
Automated Offboarding: Access rights for departing employees or contractors are revoked immediately upon termination in accordance with our Employee Termination Security Policy.
4. Secure Development & Vulnerability Management
Secure SDLC: Development workflows adhere to secure Software Development Life Cycle (SDLC) practices designed to mitigate OWASP Top 10 security risks.
Peer Reviews & Automated Scanning: All code commits undergo mandatory peer review and automated dependency scanning via GitHub Secret Scanning and vulnerability detection tools before deployment.
Penetration Testing: Annual third-party penetration tests are conducted to proactively identify and remediate potential application or infrastructure vulnerabilities.
5. Incident Response & Business Continuity
24/7 Security Alerting: Automated CloudWatch and Vanta alerts notify engineering and security leadership immediately upon detecting security anomalies or system health degradations.
Incident Response Plan (IRP): Formally documented and annually tested through tabletop simulation drills to ensure rapid triage, containment, eradication, and post-incident reporting.
Disaster Recovery (DR): Automated continuous database snapshots and backups are encrypted and stored across secondary locations to guarantee low Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
6. Personnel & Administrative Security
Background Checks: All active personnel undergo pre-employment background screening.
Confidentiality & NDAs: Employees sign non-disclosure and proprietary information agreements upon onboarding.
Security Awareness Training: Mandatory annual security and privacy awareness training is completed by all team members via Vanta.
Dedicated Security & Support Contacts
Have questions about our security practices, or need to report a potential vulnerability?
General Support & Security Inquiries: support@saleschoice.com | help@saleschoice.com