Security
Security at infoodle is taken seriously. We have endeavoured to ensure that any data stored with infoodle is kept safe and that the use of the system does not create openings for unauthorised access either by external users, or legitimate users to access data they should not be accessing.
Security needs to be considered at many points, this document is intended to provide information on the steps we have taken.
Organisational Security
Internal Policies
infoodle has defined and implemented policies and procedures across our business processes. The policies are designed to protect the confidentiality, availability and integrity of infoodle and security of client information and resources. These policies cover various technical and business processes including key security areas of server maintenance and password security.
Employee Vetting
Each employee is vetted before they formally join the company, this includes vetting of criminal records, previous employment records if any, educational background and various other publicly available information resources.
Training and awareness
Security awareness is part of our culture, training content is created and circulated within different teams to ensure that all employees of infoodle are aware of information security policies, emerging threats and common attack vectors. In addition to this, security awareness sessions are conducted to raise awareness about the threats, security practices and company policies.
Server Security
Physical security
The servers are hosted by various Amazon data centres which is a premier hosting provider. Data centres are chosen that are closest to our clients to ensure good performance and safe harbour for data compliance reasons. The servers are monitored at various points by both infoodle and the hosting companies to ensure uptime.
Traffic security
The data that passes between the user and the server is encrypted using a secure mechanism. You will notice all sites use https rather than http to identify this.
The server is protected using external firewalls and upstream traffic management to control external attacks, and further internal firewalls to provide more advanced protection.
Server Monitoring
infoodle servers are monitored actively 24/7 in order to alert the technical staff to any issues or unexpected behaviour. This monitoring covers not only things like how hard the server is working but how many of our team’s accounts are being used and if our services are down.
Server Access
Significant steps have been taken to ensure only infoodle technical staff are able to login. This is done using personal passworded keys from our own private network. This means even if a user’s key and password is compromised, without access to our own private network the intruder will not be able to gain access.
Server Software Updates
Updates to server software repositories are checked once a day and reported via monitoring. Updates are installed and tested in a test environment followed by the roll-out to the production environment. This process is usually done within 24 hours for non-disruptive updates.
Updates that require server restarts that could affect client facing services are usually installed within 72 hours in case of ‘critical’ updates and within 7 days in case of non-critical updates.
Database security
The core of your secure data is stored in the database, be it your contact records or financial data, you can rest easy knowing we have you covered. infoodle protects the databases with data-at-rest encryption, meaning that without special keys made available only to infoodle servers via a secure connection to an externally configured secure key service, no data can be read from your database, or its backups.
File security
The second place your data can be stored when it’s not in the database is as a file. These are stored in one of two places, both of which are secured for access to ensure that only your instance of infoodle can write to or read from your file store.
Service Status Disclosure
As part of infoodle’s incident response procedure, we have made it a priority to disclose any issues to our users so you know as soon as we do if there is an issue with the system. This ensures that if there is an outage it has as little impact on the clients as possible. You can monitor our services status and review our history at infoodle’s Status page.
Backups
Backups are taken daily and stored in two separate physical locations. These are retained for no less than 14 days. Access to the backup files is limited to just infoodle technical staff. Our backups are encrypted during transfer and at storage.
Backups are stored in two physical locations to ensure accessibility of data even in the unlikely event of a disaster interrupting services at both the live services as well as one of our backup locations.
infoodle Application Security
The software has been built to ensure that any requests to the server are fully validated in order to prevent unauthorised access to the site.
Two factor authentication
infoodle comes configured with two factor authentication enforced for all users. The main reason behind adding two factor authentication to your login process is enhancing the security of your account. Extra security means that even if someone steals your password in a phishing attack, they will still need your 2FA device in order to gain access to your account. If your computer gets hacked or stolen, the attackers still need your 2FA device to log in.