Security Standards at Userpilot
GDPR
SOC 2 Type II
HIPAA
Security
Internal security
- Data encryption
All of our projects undergo routine security assessments, including regular penetration tests conducted by certified auditors. If you would like to receive a copy of the reports, kindly contact [email protected]. Please be advised that parties requesting access to our penetration test reports are required to sign a Non-Disclosure Agreement (NDA) before the information can be shared. Additionally, authentication keys are securely hashed, and we employ AWS tools for the management of production secrets.
Product security
Network and application security
- Failover and Disaster Recovery
- Our infrastructure and data are spread across Multi AWS availability zones and will continue to work should any one of those data centers fail.
- Virtual Private Cloud, all of our servers are within our own virtual private cloud (VPC) with network access control lists (ACLs).
- Permissions are controlled and Authentication is required and logged.
- Access to customer data is limited to authorized employees who require it for their job, ticketing regarding access to data is tracked and monitored.
- Incident Response, Userpilot implements a protocol for handling security events which includes escalation procedures according to a Risk Metric.
Additional Security features
- Userpilot provides annual Security & Awareness Training for general purposes as well as HIPAA security training.
- Confidentiality - All employee contracts include a separately signed confidentiality agreement
- All credit card payments made to Userpilot go through Stripe. Details about their security setup and PCI compliance can be found at Stripe’s security page.
Availability
Backups
GDPR compliance with Userpilot
- View the API docs for HTTP DELETE [https://docs.userpilot.com/article/189-delete-users-and-companies].
- Monitor deletion status and requests
- Track the progress of deletion requests to confirm when data is finally deleted, so you can update your users.
- View the API docs for background jobs tracking. [https://docs.userpilot.com/article/189-delete-users-and-companies]
- The rights of access, portability, and rectification Compile user data for access and portability requests
- Export user data to open format (CSV) to organize data about a given user, so you can easily share it if requested.
SOC2 Type II Certification
- Has access control via end-to-end encryption and two-factor authentication. You can learn more about the technologies used to ensure data security in a report issued by a reputable, independent auditor.
- Uses network and application firewalls
- Has intrusion-detection mechanisms in place
- Uses performance monitoring tools
- Uses disaster recovery tools
- Has security incident handling procedures in place
- Uses quality assurance and process monitoring procedures
Current and potential customers of Userpilot can now be sure about its data protection mechanisms quality and can learn all the details from the SOC 2 report, available upon request from [email protected]
HIPAA Compliance with Userpilot
Contact
To report any issues or request more information, please drop us an email at [email protected]