Snapshot 66729
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Copyright (c) 2023, Intercom, Inc. (legal@intercom.io) with Reserved Font Name "Poppins". This Font Software is licensed under the SIL Open Font License, Version 1.1.Copyright (c) 2023, Intercom, Inc. (legal@intercom.io) with Reserved Font Name "Inter". This Font Software is licensed under the SIL Open Font License, Version 1.1.Skip to main content Security Givecloud Security Statement April 11, 2024 Table of contents Last update: April 11, 2024 Security Statement Givecloud prioritizes cybersecurity to shield against external threats and internal risks. We have established suitable management, operational, and technical controls to mitigate cyber risks, bolster resilience against cyber incidents, and safeguard against cyber threats. Complying with or surpassing the industry’s information security best practices, Givecloud implements robust security measures to defend its clients and itself. Givecloud is SOC 2 Type 2 audited, demonstrating our organization’s secure handling of your confidential data. Givecloud's payment partners are PCI DSS compliant, ensuring that all financial transactions are safe and secure. Givecloud utilizes TLS version 1.3 with 256-bit encryption, guaranteeing the highest levels of confidentiality, integrity, and privacy for all information exchanged between Givecloud and its customers. Givecloud’s service resides in a world-class data center that has passed over 20 audits and assessments by 3rd-party security assessors. Givecloud's cybersecurity program is aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF). This page offers a comprehensive overview of Givecloud's information security strategy and outlines our practices for securing information, systems, and services. Our approach is organized according to the five core functions of the NIST CSF: Identify ❖ Risk Governance Risk governance and risk management are a function of Givecloud’s management culture. Givecloud’s governance model is achieved by the day-to-day activities of managers and their teams. ❖ Asset Management Givecloud maintains an asset management system that inventories, classifies, and protects applications, information, and hardware. Givecloud’s Mobile device management implementation allows it to control, secure and enforce policies on smartphones, tablets, and other endpoints. Protect ❖ Identity and Access Management Givecloud has implemented security controls to identify, authorize, authenticate and manage individuals’ access to Givecloud’s systems and information assets. ❖ Applications and Software Security Givecloud manages application and software security through its secure software development practices, vulnerability testing, monitoring, and logging. ❖ Infrastructure Security Givecloud protects its infrastructure through vulnerability testing, system hardening, and malware protection. ❖ Data Protection and Data Privacy Givecloud has implemented security controls that are designed to safeguard Givecloud and client data. This includes the secure storage and transmission of data. ❖ Mobile Security Givecloud’s mobile solutions allow employees to conduct business activities on their personal devices while protecting Givecloud systems and client information. ❖ Physical Security Givecloud has implemented physical security controls at all Givecloud facilities including its office spaces, and cloud-based facilities. Detect ❖ Continuous Monitoring Givecloud maintains detective security controls at the network, end-point, and application layers to detect anomalous activities, potential threat activities, and indicators of compromise. ❖ Anomaly Detection Givecloud has deployed end-point protection and detection services to ensure that security anomalies and events are detected quickly, and their potential impact is understood. Respond ❖ Incident Management Givecloud’s incident management processes enable the effective detection and management of security threats and incidents that have the potential to impact the confidentiality, integrity, or availability of Givecloud’s information, applications, and services. For more information, see Givecloud's Trust Center. Recover ❖ Givecloud’s Business Continuity and Disaster Recovery processes covers both business and technology resilience. Givecloud’s cloud-based infrastructure features a highly available architecture where applications and information can be restored within their Recovery Time Objective. ←Back to main site Related Articles GDPR and Givecloud Security Measures for Carding Bots & Preventing Fraud How to Manage Your Givecloud Billing Information How does Givecloud manage high traffic/donation volume? How Givecloud Leverages OFAC Sanctions List Did this answer your question? Table of contents