Technical and organisational measures (TOMs)
Apteco applies and maintains appropriate and reasonable technical and organisational measures (TOMs) suitable and sufficient to protect any Apteco Cloud Personal Information. These measures protect that information from unauthorised or unlawful processing, and from accidental loss, destruction, or damage.
Access control¶
Professional security staff control physical access to data centres at building ingress points, utilising:
- Surveillance
- Detection systems
- Other electronic means
Data centres are certified for compliance with ISO 27001. Production Apteco Cloud servers are logically and physically secured from internal Apteco systems.
Intrusion prevention¶
Multiple protection measures are in place to prevent unauthorised access to the Apteco Cloud network, including:
- Firewalls
- Hardened operating systems to Center for Internet Security (CIS) Level 1
- Encrypted network traffic
- Password policies
- Regular penetration testing by independent, globally renowned security experts
Unauthorised activities in data processing systems¶
Multiple protection measures are in place to prevent unauthorised activities on Apteco Cloud systems, including:
- Firewall policies
- Hardened operating systems
- Regular monitoring
Apteco encrypts Apteco Cloud storage, including all customer data in Apteco Cloud, using the industry-standard AES-256 algorithm.
Separation control¶
Apteco holds a customer's data separately from other customers' data, unless previously agreed in writing. Apteco separates production, test, development, and internal environments.
Pseudonymisation and anonymisation¶
Apteco processes any personal data when running the Apteco Cloud service. This is done in such a way that the data can no longer be attributed to a specific person without additional information. This includes any telemetry data unless the person has specifically approved this, for example by participating in the Apteco Insider Programme. The client is responsible for their own data and whether that data can be attributed to a specific person.
Transfer control¶
Apteco uses industry-standard encryption for the transmission of Apteco Cloud data, including any personal data customers may hold in Apteco Cloud. This includes data uploaded to and exported from Apteco Cloud over HTTPS during transit.
Input control¶
The Apteco Cloud environment and application has built-in auditing capabilities for building the system, administering the system, and user activity. Retention periods apply for auditing and evidence purposes.
Availability control¶
Apteco regularly makes backups of Apteco Cloud instances and tests the recovery process. Apteco retains the last three daily backups and the last four weekly backups. The administration of Apteco Cloud has additional measures in place to protect data from accidental destruction. The Apteco software includes many features that contribute to a secure environment, for example, limiting the velocity of data that users can export.
Resilience and fail-safe control¶
Apteco has built Apteco Cloud on a resilient infrastructure and a hardened operating system. This conforms to industry standards defined by the Center for Internet Security (CIS). Apteco maintains communication channels with the relevant agencies and suppliers to stay informed about updates and patches. Apteco maintains separate development, test, and production environments. Apteco also takes proactive measures on code changes to identify risks before they reach production environments.
Order control¶
Apteco employee contracts include clauses requiring employees to maintain client confidentiality. Apteco doesn't subcontract the support of Apteco Cloud.