SAReye employs a cloud deployment model for its software-as-a-service (“SaaS”) solution. All software maintenance and configuration activities are conducted by SAReye employees. SAReye employs industry standard practices for security controls such as firewalls, intrusion detection, and change management.
SAReye distributed architecture for data collection and processing allows it to scale horizontally as the number of clients and volume of traffic increases. SAReye uses multiple monitoring processes and tools to continuously track network resources, operating systems, applications and capacity. Systems are scaled up when predetermined capacity thresholds are reached.
SAReye has practices in place as part of its business continuity planning to assist management in identifying and managing risks that could affect the organization’s ability to provide reliable services to its clients. These practices are used to identify significant risks for the organization, initiate the identification and/or implementation of appropriate risk mitigation measures, and assist management in monitoring risk and remediation activities.
SAReye maintains, and annually updates, a general written Information Security & Access Policy, which details employee’s responsibilities toward confidentiality of client data and acceptable use of resources. All staff must review and sign this policy during on-boarding.
Only authorized personnel can administer systems or perform security management and operational functions. Authorization for and implementation of changes are segregated responsibilities wherever appropriate to the organization. Access to client data is restricted to legitimate business use only.
SAReye employees are required to undergo background checks and provide specific documents verifying identity at the time of employment.
General information security responsibilities are documented in SAReye Information Security & Access Policy, which all employees must sign as part of their onboarding.
General information security training is provided to all new employees (both full time and temporary) as part of their onboarding. A compulsory annual security and privacy training requirement ensures employees refresh their knowledge and understanding. Additional security training is also provided to employees who handle client data.
SAReye manages a formal termination process, which includes removal of any potential access to SAReye and related data. The exit interview reminds ex-employees of their remaining employment restriction and contractual obligations.
All critical and repeatable processes and security checks in SAReye production environment are either documented in procedures or implemented as automation scripts. SAReye maintains and follows formal change management processes. All changes to the production environment (network, systems, platform, application, configuration, including physical changes such as equipment moves) are tracked and documented. All relevant business owners such as Support, Engineering, and DevOps, Security are represented at regular change management meetings.
Both scheduled and emergency changes are tested in separate environments, reviewed and approved by Engineering, and Technical Support before deployment to the production environment. Testing, other than deployment validation, is prohibited in the production environment.
SAReye stores all client data in fully redundant databases. Daily and intraday data is backed up on a scheduled basis and stored in a geographically separated location. Backups are stored for 30 days and are then purged. All database backups are securely encrypted with a 2048-bit GPG key.
SAReye uses an industry standard enterprise application management solution to monitor systems 24/7, trigger alerts based on event logs, and to facilitate alerting, trend analysis, and risk assessment.
SAReye clients access the SAReye environment via the public Internet. Data transfers from SAReye API can only use TLS / HTTPS.
SAReye follows an agile development methodology in which products are deployed on an iterative, rapid release cycle. Security and security testing are implemented throughout the entire software development methodology. Quality Assurance is involved at each phase of the lifecycle and security best practices are a mandated aspect of all development activities.
Business continuity planning (BCP) and disaster recovery (DR) activities prioritize critical functions supporting the delivery of SAReyes SaaS Solutions to its clients. The development and scope of BCP and DR in each business function reflects the criticality of each function and/or facility in order to maximize the effectiveness of these efforts. SAReye ensures that a disaster recovery copy is always accessible and ready to be set up in a backup hosting facility.
SAReye SaaS Solutions architecture utilizes redundancy through the entire infrastructure, from load balancers, storage units and processing engines. No system or device has a single point of failure. Data is always written to two separate locations when stored.