Snapshot 70685
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Platform Trust Security at Blue Canvas We care about the safety and stability of our platform here at Blue Canvas, and are deeply committed to protecting your information. SOC 2 certified safety and reliability We protect your metadata and help your team stay compliant. Security is part of our design. Blue Canvas passed a full SOC 2 audit, meeting high standards for product, infrastructure, and policies. Contact us for the report Security is something we prioritize at Blue Canvas. We believe that security must be deeply ingrained in the process — it's more than just firewalls and password rotation. Security is also about culture and policies. We have set out to build a security-literate and conscious culture from day one. This ranges from the way we think about hiring and training, to the vendors that we select, to how we implement our systems. Everyone on the team is trained in security best practices, including two-factor authentication, proper password management, and encryption. Many young companies treat security as an afterthought. We understand the pressure many feel to do this, but we believe that making a conscious strategic investment in security best practices at an early stage is crucial for us and our customers. Infrastructure Security Secure infrastructure provides the basis for a trustworthy application. We build on Amazon Web Services (AWS) for their industry leading security focus and best practices. AWS physical facilities, networks, hardware, and operational software is designed and managed according to security best practices and a variety of security compliance standards, including: ISO 27001, PCI DSS Level 1, HIPAA, and SOC 1, 2, and 3. AWS Physical Security AWS offers strictly controlled physical access, monitored by professional security staff. Video surveillance and intrusion detection systems monitor all data center access Authorized staff pass two-factor authentication a minimum of two times to reach data center floors Automatic fire detection and suppression systems and fully redundant power systems End-of-life hardware goes through a strict decommissioning process, destroying data with practices described in DoD 5220.22-M or NIST 800-88 AWS Network Security AWS provides secure network architecture using firewalls and other boundary devices to monitor communications at external boundaries of the network and key internal boundaries. Boundary devices employ access control lists (ACL) Designed specifically to protect against DDoS, man-in-the-middle attacks, IP spoofing and port scanning Packet sniffing by other AWS tenants is not possible — even two virtual instances owned by the same customer on the same physical host cannot listen to each other's traffic Salesforce API Security We leverage security mechanisms provided by Salesforce to protect access to privileged APIs and authentication tokens. We process all authentication and delegation through Auth0, a purpose built, certified authentication platform. Auth0 acts as the IdP and delegation endpoint for our own user authentication, as well as the connections established between Blue Canvas and the Salesforce APIs. Auth0 is compliant and certified under SOC 2 Type II and HIPAA BAA. OAuth 2.0 Authentication Authentication with Salesforce is based on an OAuth 2.0 flow. This ensures that the username/password credentials (and 2-factor if enabled) are handled only by Salesforce.com and never exposed to us directly. After signing in, the user approves our Connected App. To access the Salesforce API for synchronization, our backend servers request a short-lived access token from a restricted delegation endpoint. Access tokens are never stored at rest. Each delegation attempt is audit-logged and can be reviewed by us in our Auth0 backend — and by you in your Salesforce Org. Certificate-Based Token Exchange The delegation endpoint forwards requests to Salesforce, authenticated using certificate-based (RS256) client assertions. This secure, certificate-based exchange offers strict controls to protect access to the underlying certificate. It is preferable over the more commonly seen exchange of long-lived refresh tokens — since there are no long-lived tokens, the attack surface is decreased. You can independently monitor access from Blue Canvas to your Salesforce Orgs through the Connect Apps OAuth Usage feature provided by Salesforce — and, if necessary, use it to completely revoke API access. Audit Logs Salesforce independently keeps logs of all security events that happen on their systems, so you can independently audit every request that Blue Canvas makes. Application Security Blue Canvas has controls in place to protect the security of application services, customer data and system configuration. Access to production servers is controlled by network isolation and firewalls. Changes to application software and system infrastructure are tracked in version controlled code repositories. Authenticated Access Blue Canvas APIs and applications are only accessible over encrypted TLS/SSL channels. Every request requires authentication with a time-limited access token, issued by the authentication subsystem described above We utilize 2048-bit RSA keys with a modern cipher suite to strengthen encryption Server certificates are securely stored using AWS Certificate Manager and cannot be accessed directly Logging All infrastructure API requests — administrative management access, storage access, or changes to infrastructure configuration — are logged permanently using AWS CloudTrail Authentication activity, such as end-user sign-ins, password changes, administrative access, and API token delegation, is logged independently for us by Auth0 Rate Limiting Blue Canvas applications have built-in rate limiting and block excessive requests to ensure service quality and availability Excessive brute-force attempts to sign into a user account are detected and blocked automatically Change Management Changes to Blue Canvas application software are executed through automated build verification and deployment processes, and code modifications are visible in our version control system Infrastructure is managed and changed through declarative configuration files stored and versioned in our code repository Changes are rolled out to minimize impact on our customers and on service availability Network Protection By default, all traffic from external networks is blocked and no traffic is allowed to directly access Blue Canvas servers and services Firewalls regulate traffic into our private non-routable IP networks API and application requests are processed by proxy services and load balancers before they are handed off to our internal servers Security questions or issues? If you have found a security vulnerability within Blue Canvas, please get in touch with our security team. Read more about Responsible Disclosure, Privacy Policy, and Terms of Service. Request security documents Doing a vendor review? Tick the documents you need and we'll send them over by email. SOC 2 Report Pentest Report Copy of Cybersecurity Insurance Need something else? Email us at support@bluecanvas.io. Start your DevOps journey today Over 850 million lines of code are securely backed up with Blue Canvas, empowering enterprises to continuously deploy and rollback in Salesforce with ease and maintain environment parity across orgs. Schedule a demoStart your Free Trial