| |
|
OrcaEyes Takes Data Security Very Seriously
When you entrust us with your employee data, we implement the most innovative and effective measures at every level of application delivery to ensure your information is protected. OrcaEyes has adopted HIPAA standards for setting password, security clearance and technical security practices.
Application security
The OrcaEyes application employs extensive security measures to protect against the loss, misuse and unauthorized alteration of data.
- Secure Socket Layer (SSL) technology protects information using both server authentication and data encryption to help ensure that data is safe, secure and available only to you.
- OrcaEyes requires unique user names and passwords that must be entered each time a user logs on and must be HIPAA compliant.
Data Transfer Security
OrcaEyes knows the importance of keeping your employee and business data safe and secure, so we take strong measures to ensure its protection.
- Multiple transfer methods are supported, including secure HTTP (HTTPS), and secure FTP (FTPS – recommended).
- OrcaEyes supports and recommends PGP encryption prior to file transfer. PGP is the most trusted, secure encryption method on Earth (the FBI has tried and failed to break PGP encryption).
Personal Information
Personal identifiers (employee ID, social security number, and name) are not required for system use.
Anti-virus security
OrcaEyes conducts monthly penetration tests. Patches are updated weekly or upon alert of a major security threat (IE a "zero day" type vulnerability).
Network protection
OrcaEyes utilizes best-in-class network equipment, including firewall, switches and intrusion detection.
- Perimeter firewalls and edge routers block unused protocols.
- Internal firewalls segregate traffic between the application and database tiers.
Hosting Center Security
OrcaEyes state-of-the-art hosting facilities takes the following measure to protect your information.
- Access control and physical security.
- Secure data centers in top-tier hosting facilities.
- Level 3 technicians provide 24-hour manned security.
- Security cameras monitor activity throughout the facility, including equipment areas, corridors and mechanical, shipping and receiving areas.
- Motion detectors and alarms are located throughout the facilities, and silent alarms automatically notify security and law enforcement personnel in the event of a security breach.
Information security incident management
OrcaEyes has put in place monitoring services for 24/7 managed network security and monitoring. These monitoring services help eliminate network vulnerabilities. Real-time notifications of vulnerabilities and security incidents are entered into the OrcaEyes ticketing system and the appropriate OrcaEyes personnel are notified.
- Backup, failover and redundancy
- Backup encryption. All data stored on backup tapes is encrypted using 128-bit encryption.
- Backup and restore. Full data back-ups weekly and incremental data backups nightly.
- Geographical failover. OrcaEyes offers geographical failover as an optional service.
- Application server clusters are available on a per-client basis to ensure that if servers fail, it will not interrupt the user experience.
Uptime Monitoring
OrcaEyes uses the Nagios product to monitor uptime of critical customer-facing services 24/7. These include:
- Access to SonarVision
- Access to DepthFinder
- Access to SonarVision on Demand
- Database connection up (verify that back/data-end of products is working)
- FTP connections up (file transfer availability)
|
|