Trust is the basis of everything we do
Ä¢¹½ÊÓÆµ is continually refining its security strategy and framework?to reflect our organization¡¯s specific security risks. Maintaining a robust security-first culture is key to protecting the integrity of our products and services, inspiring customer confidence, and furthering our business relationships.
Ä¢¹½ÊÓÆµ knows that customers care about how personal data is used and shared, and Ä¢¹½ÊÓÆµ takes privacy very seriously. Ä¢¹½ÊÓÆµ¡¯s privacy and risk management framework is designed to meet Ä¢¹½ÊÓÆµ¡¯s obligations under applicable global privacy laws , including the General Data Protection Regulation (GDPR).
Ä¢¹½ÊÓÆµ undergoes third-party audits and obtains product certifications to provide our customers with independent, third-party assurances.
Ä¢¹½ÊÓÆµ designs our Cloud Service offerings to deliver secure, highly available solutions, 24×7, around the world.?Ä¢¹½ÊÓÆµ Support offers 24x7x365 issue resolution, a global logistics network, and robust online resources for all products.
Ä¢¹½ÊÓÆµ¡¯s security strategy and framework leverages industry standard best practices and standards. Our security program is led by Ä¢¹½ÊÓÆµ¡¯s Chief Information Officer (¡°CISO¡±) with the involvement of key cross-functional stakeholders to enable a holistic approach to security management. Key features of Ä¢¹½ÊÓÆµ¡¯s security program include:
Ä¢¹½ÊÓÆµ maintains a comprehensive set of security policies. More information regarding the security requirements and measures used to establish and enforce Ä¢¹½ÊÓÆµ¡¯s corporate security program can be found?here.
The technical and organizational measures built into specific offerings can be found?here.
All Ä¢¹½ÊÓÆµ personnel are required to undergo annual security training and participate in ongoing security awareness initiatives.
Ä¢¹½ÊÓÆµ does not operate any of its own data centers. We leverage industry-leading third- party cloud infrastructure providers and requires all such providers to have?a SOC 2 Type II annual audit and ISO 27001 certification, or industry recognized equivalent frameworks.
Engineering teams regularly review our code, infrastructure, and supporting systems to ensure we have the correct people, processes, and controls to protect product development and customer data.
Our security incident response team acts promptly to respond, investigate, and remediate security issues when they are detected..
Ä¢¹½ÊÓÆµ knows that customers care about how your personal data is used and shared, and Ä¢¹½ÊÓÆµ takes privacy very seriously. The Privacy page of Ä¢¹½ÊÓÆµ¡¯s Trust Center provides a centralized source of information about Ä¢¹½ÊÓÆµ¡¯s privacy practices.
We value the trust you place in Ä¢¹½ÊÓÆµ. We are committed to providing our customers and partners with secure solutions utilizing state of the art technologies to safeguard your information.
Ä¢¹½ÊÓÆµ¡¯s security and privacy framework is governed by the ISO/IEC 27001:2022 Information Security Standard and the ISO/IEC 27701:2019 Privacy Information Management Standard. Ä¢¹½ÊÓÆµ has achieved internationally recognized ISO/IEC 27001:2022 and ISO/IEC 27701:2019 certifications. In addition, a subset of Ä¢¹½ÊÓÆµ solutions has also undergone Statement on Standards for Attestation Engagements (SSAE) 18 System and Organization Controls (SOC) audits. To maintain these certifications, Ä¢¹½ÊÓÆµ undergoes comprehensive annual audits from an independent third-party assessment organization. These security assessors verify Ä¢¹½ÊÓÆµ¡¯s compliance in over 140 security and data protection areas within 14 different security categories including access control, incident response, security training, system integrity, identification and authentication, contingency planning, etc.
Established by the International Organization for Standardization (ISO), the prestigious and internationally recognized ISO 27001 standard requires the certification of an organization¡¯s information security management controls for areas such as data security and business continuity. Ä¢¹½ÊÓÆµ¡¯s Information Security and Privacy Management System (ISPMS) has been inspected and certified by Coalfire, an accredited certifying body. The Ä¢¹½ÊÓÆµ solutions that are ISO 27001 certified include Ä¢¹½ÊÓÆµ IQ and Ä¢¹½ÊÓÆµ Aternity Digital Experience Management, including Aternity Employee Experience, Application Performance Management (APM), and NPM+.
Ä¢¹½ÊÓÆµ¡¯s ISO 27001 certificate is? available here.
Established by the International Organization for Standardization (ISO), the prestigious and internationally recognized ISO 27701 standard requires the certification of an organization¡¯s management controls for privacy.? Ä¢¹½ÊÓÆµ¡¯s Information Security and Privacy Management System (ISPMS) has been inspected and certified by Coalfire, an accredited certifying body.? The Ä¢¹½ÊÓÆµ solutions that are ISO-certified include Ä¢¹½ÊÓÆµ IQ and Ä¢¹½ÊÓÆµ Aternity Digital Experience Management, including Aternity Employee Experience, Application Performance Management (APM), and NPM+.
Ä¢¹½ÊÓÆµ¡¯s ISO 27701 certificate is available here.
Ä¢¹½ÊÓÆµ publishes a Service Organization Controls 3 (SOC 3) report for the Ä¢¹½ÊÓÆµ IQ and Ä¢¹½ÊÓÆµ Aternity Digital Experience Management Platforms. This SOC 3 report is a publicly available summary of the detailed SOC 2 Type II report.? The SOC 3 report provides assurance that Ä¢¹½ÊÓÆµ¡¯s internal controls have been verified to achieve the AICPA¡¯s Trust Services Criteria for data security and availability.
The detailed SOC 2 Type II report may be requested from your account executive.
Click here for the Ä¢¹½ÊÓÆµ IQ and Ä¢¹½ÊÓÆµ Aternity SOC 3 report.
Australia IRAP
The ?(IRAP) provides a comprehensive process for the independent assessment of a system¡¯s security against the Australian Government ?(ISM) requirements. The IRAP goal is to maximize the security of Australian federal, state, and local government data by focusing on the information and communications technology (ICT) infrastructure intended for data storage, processing, and communication.
In May 2024, CyberCX, a third-party assessor, completed the Cloud Security Assessment of the Australian regions for the Ä¢¹½ÊÓÆµ Aternity EUEM Cloud Service. The assessment was conducted in-line with the Australian Cyber Security Centre¡¯s (ACSC) Cloud Security Assessment and Authorisation Framework, Phase 1. The assessment was conducted using the Australian Government Information Security Manual (ISM) March 2024 version. The Aternity EUEM Cloud Service was assessed at the PROTECTED information classification level. A copy of the assessment may be requested from your account executive.
Ä¢¹½ÊÓÆµ also contracts with Coalfire, an industry-leading penetration testing firm, to perform rigorous security testing of its Ä¢¹½ÊÓÆµ IQ and Ä¢¹½ÊÓÆµ Aternity solutions. A copy of the most recent penetration test may be requested from your account executive.
Ä¢¹½ÊÓÆµ publishes service level agreements (¡°SLAs¡±) for its cloud services?here.
Ä¢¹½ÊÓÆµ provides 24×7 follow-the-sun support for its products as described?here.
Ä¢¹½ÊÓÆµ¡¯s Business Continuity Planning (¡°BCP¡±) Statement can be found?here.
Ä¢¹½ÊÓÆµ uses select forms of Artificial Intelligence (¡°AI¡±) in certain products.
Ä¢¹½ÊÓÆµ IQ
For information about AI in Ä¢¹½ÊÓÆµ IQ, click here.
Ä¢¹½ÊÓÆµ IQ Assist
For information about AI in Ä¢¹½ÊÓÆµ IQ Assist, click here.
Selected Country/Language: English