Security Protecting your data and our services is our top priority. The availability, confidentiality, and integrity of your data matters as much to us as it does to your business. We use multiple safeguards to protect this information and are constantly monitoring and improving our products and services. Our data center Klipfolio hosts our applications and your data with Amazon Web Services (AWS), an industry leader in secure, scalable cloud infrastructure. Additional resources from AWS:
  • Overview of AWS Cloud Security
  • AWS Security Processes
  • AWS Security Blog
  • AWS Compliance
  • Physical security AWS data centers use professional security staff, video surveillance, intrusion detection, and multi-factor authentication to control physical access. Only authorized personnel with a legitimate business need can enter. All access is logged and routinely audited, and visitors require ID and an escort. AWS maintains SOC, PCI, ISO, and other certifications — details are on the AWS Compliance page. Environmental security Every data center has automatic fire detection and suppression, fully redundant power systems, and UPS/backup generators for critical loads. Climate and temperature are precisely controlled, and all equipment is monitored and maintained to ensure continued operability. Business continuity AWS infrastructure is built for high availability and tolerates system or hardware failures with minimal customer impact, under the direction of the Amazon Infrastructure Group. Core applications run in an N+1 configuration, so traffic can load-balance to remaining sites if a data center fails. Klipfolio deploys across multiple Availability Zones so we keep running even if we lose an Amazon data center. Secure transmission and sessions Connections to Klipfolio are secured via TLS 1.2 with SHA-256 certificates, ensuring an encrypted connection from your browser to our services. Sessions end after 30 minutes of inactivity or on sign-out. Access controls Users set their own IDs and passwords — we never use one-time passwords. Password strength and login-attempt limits are configurable, and passwords are encrypted. Group- and role-based permissions give full control over what each user can see and do, and a detailed event log captures authentication, failed logins, and asset creation, deletion, and modification. Servers require 2048-bit RSA keys for access — no passwords. Keys are unique per administrator or service account and never shared. Network-level firewalls block unauthorized traffic from reaching data center servers. Backups Data is backed up daily and weekly, with master/slave replication for hot-swappable database backups. Backups are stored in separate Amazon data centers from the primary Klipfolio application, so they're recoverable even if the primary center is lost. Code testing and assessments We test all code for security vulnerabilities before release and regularly scan our network and systems, including:
  • Application vulnerability threat assessments
  • Network vulnerability threat assessments
  • Selected penetration testing and code review
  • Security control framework review and testing
  • Security monitoring Our team monitors notifications from multiple sources and alerts from internal systems to identify and manage threats.