Information Security & Privacy

Your Data is
Safe with Us.

At Elemetrik, we take the security of your data very seriously. Many of our customers come from the most highly regulated and security-sensitive industries in the world, with a wide variety of security and privacy needs. We understand the importance and sensitivity of client and employee data, and are committed to maintaining high information security and privacy standards at all times.

  • Secure
    data hosting
  • ISO 27001:2022
    certified
  • GDPR
    compliant
  • SOC Type II
    compliant

Independently audited.
Privacy by design.

Globally recognised standards, validated by third parties and built into how we develop every feature.

ISMS

ISO 27001:2022 Certified

A globally recognised, standards-based approach to information security management. All standards and regulations are validated by independent third-party audits.

  • Our information security and privacy team conducts risk assessments and prepares risk treatment plans to mitigate any identified risks, helping us continuously improve our security controls.

All ISMS policies are implemented and available on request.

Data protection

GDPR Compliant

Companies using our products need to collect, store and share the personal data of clients and their candidates or employees. We ensure individuals’ data is processed transparently and only for the specific purposes for which it was collected.

  • We have taken technical and organisational measures so that processing of personal data meets the requirements of applicable data protection law.

New product features are built on “privacy by design” principles.

Data encryption

Encrypted in transit.
Encrypted at rest.

Every layer, from the browser to the database, is protected with industry-standard encryption.

  • Data in transit is protected with TLS, encrypting data between server and browser. We use SSL certificates with TLS 1.2 and above, and data is transmitted over HTTPS.
  • Sensitive data is encrypted with AES 256 (Advanced Encryption Standard block cipher) and stored in the database.
  • AWS KMS (Key Management Service) encrypts data within applications and controls encryption of stored data.
  • Login credentials are encrypted using hashing and stored in the database.
  • Active Directory authentication is available on client request.

Hosting & continuity

Always backed up.
Always available.

Elemetrik databases and servers are hosted on AWS (Amazon Web Services), offering efficient, re-sizable capacity with high availability and easy scalability.

99.999%

Availability assured by AWS for our hosting infrastructure

Data Center & Environmental Security

The Elemetrik application and servers are hosted in the AWS (Amazon Web Services) environment.

Access

MFA is enabled on the devices of authorised DevOps, and root account access is strictly restricted.

Logging

CloudTrail and CloudWatch are used across all regions for logging and monitoring, keeping a history of AWS API calls for an account.

Recovery

In the event of a network or hardware failure, the application can easily be set up in a different region and services restored quickly.

Monitoring

All services are continuously monitored. If services are interrupted, our production support team is alerted and the issue is attended to immediately, ensuring the best possible uptime.

Data Backup

Data is backed up regularly, and all backups are verified monthly to ensure they are restorable. We offer the following AWS-based backup mechanisms:

Automated backup

Automatically performs a full daily snapshot of a database’s data.

Point-in-time snapshots

User-initiated RDS database snapshots. Unlike the once-a-day automated backup, these can be taken as many times as needed.

Network & application security

Layered defences,
built in from day one.

Network Security

Security within our cloud server is provided on multiple levels, each building on the capabilities of the others. The goal is to prevent data on the server from being intercepted by unauthorised systems or users, and to make the network and cloud environment as secure as possible.

PlusIntrusion prevention & detection (IPS/IDS)
Layer 3SSL/TLS-signed HTTPS request calls
Layer 2Firewall
Layer 1Operating system of the host platform
Data on the server

Development Process

Our development and QA teams are trained regularly on web application security threats and how to avoid them. We conduct regular VAPT for our applications based on OWASP principles.

Application and network-level security is in place to protect the software against issues such as:

Protected against

  • DDoS attacks
  • Man-in-the-Middle (MITM) attacks
  • IP spoofing
  • Port scanning
  • Packet sniffing by other clients

Endpoint security

Secured right down to every device.

Endpoint controls, including restricted internet access at network and system level, are implemented. We secure our network perimeter, endpoints and policies using the following solutions.

Antivirus & antimalware

Endpoints are protected by enterprise antivirus and antimalware solutions, formally approved as our official defence against malware of any kind.

Unified threat management

UTM is installed, covering firewall, IPS/IDS and content filtering.

Access restriction policies

Domain Controller and Active Directory policies govern access restrictions across managed devices.

Mandatory VPN

All connections are secured over VPN.

Security & privacy

Have a security question?

For any questions or requests for additional information, feel free to email us at helpdesk@elemetrik.co

New message
Tohelpdesk@elemetrik.co
SubjectSecurity question