Security
Security Program and Risk Management
色盒直播 has established a comprehensive security program based on AICPA Trust Services Criteria (TSC) 2017 for security, confidentiality, availability, processing integrity, and privacy.
色盒直播 performs an annual risk assessment to gain an accurate and comprehensive identification, review, and remediation of risks and vulnerabilities that may impact the platform's commitment to security, confidentiality, availability, processing integrity, and privacy.
Compliance
色盒直播 platform is SOC 2 Type 2 compliant against security, confidentiality, availability, processing integrity, and privacy.
For a copy of the SOC 2 Type 2 report, please submit a request to and inform your account manager.
Data encryption in-transit and at-rest
色盒直播 enforces TLS1.2 and above for data in transit between its users and the platform.
色盒直播 production data is encrypted at rest using AES-256 encryption.
鈥
SAML 2.0 SSO
色盒直播 supports the industry standard SAML 2.0 protocol for authentication using an external identity provider.
Confidentiality and Monitoring
色盒直播 enforces principles of least privilege and enforces access to data on a need to know and operate basis.
色盒直播 has established extensive audit and monitoring controls to help ensure auditability of access functions performed internally and externally.
色盒直播 platform enforces granular role-based access control for its users.
Network Protections
色盒直播 has implemented private networking, firewalls, and segmentation controls through its suppliers to ensure alignment with best practices on its network infrastructure.
Penetration Testing
色盒直播 performs targeted and general penetration testing on its platform on at least an annual basis.
Vulnerability Management
色盒直播 performs real-time static code analysis for core application code as part of the deployment process.
色盒直播 performs container vulnerability scanning as part of its deployment process.
色盒直播 has established a vulnerability management process that addresses risks in the following target SLA:
Zero Day / Critical: 7 days
High: 30 days
Medium: 90 days
Low/Info: 180 days+ (dependent on overall risk assessment)
Supplier Risk Management
色盒直播 has implemented a comprehensive supplier risk management policies and procedures to ensure protection of assets and data that are accessible by its suppliers and to establish standards for information security, privacy, and service delivery from its suppliers.
Human Resources Security
色盒直播 conducts background checks for all applicants selected for full-time employment.
色盒直播 employees and related entities are subject to continuous security awareness training with a minimum annual cadence.
Business Continuity and Availability
色盒直播 has documented and implemented a business continuity and disaster recovery plan that may be activated in case defined disruptions.
色盒直播 enforces automated daily backups for its databases on multiple zones.
色盒直播 tests its business continuity and disaster recovery scenarios at least annually.
Reliability and Capacity Monitoring
色盒直播 has a comprehensive monitoring system that helps to ensure the reliability of the platform and its related components.
Bug Bounty and Vulnerability Reports
色盒直播 does not currently have a formal bug bounty program but we encourage all researchers to submit identified vulnerabilities with a summary and a proof of concept (POC) to security@partnerstack.com and our team will respond as soon as possible.