SecurityProtecting your data and our services is our top priority. The availability, confidentiality, and integrity of your data matters as much to us as it does to your business. We use multiple safeguards to protect this information and are constantly monitoring and improving our products and services.Our data centerKlipfolio hosts our applications and your data with Amazon Web Services (AWS), an industry leader in secure, scalable cloud infrastructure. Additional resources from AWS:
Overview of AWS Cloud Security
AWS Security Processes
AWS Security Blog
AWS Compliance
Physical securityAWS data centers use professional security staff, video surveillance, intrusion detection, and multi-factor authentication to control physical access. Only authorized personnel with a legitimate business need can enter. All access is logged and routinely audited, and visitors require ID and an escort.AWS maintains SOC, PCI, ISO, and other certifications — details are on the AWS Compliance page.Environmental securityEvery data center has automatic fire detection and suppression, fully redundant power systems, and UPS/backup generators for critical loads. Climate and temperature are precisely controlled, and all equipment is monitored and maintained to ensure continued operability.Business continuityAWS infrastructure is built for high availability and tolerates system or hardware failures with minimal customer impact, under the direction of the Amazon Infrastructure Group. Core applications run in an N+1 configuration, so traffic can load-balance to remaining sites if a data center fails. Klipfolio deploys across multiple Availability Zones so we keep running even if we lose an Amazon data center.Secure transmission and sessionsConnections to Klipfolio are secured via TLS 1.2 with SHA-256 certificates, ensuring an encrypted connection from your browser to our services. Sessions end after 30 minutes of inactivity or on sign-out.Access controlsUsers set their own IDs and passwords — we never use one-time passwords. Password strength and login-attempt limits are configurable, and passwords are encrypted. Group- and role-based permissions give full control over what each user can see and do, and a detailed event log captures authentication, failed logins, and asset creation, deletion, and modification.Servers require 2048-bit RSA keys for access — no passwords. Keys are unique per administrator or service account and never shared. Network-level firewalls block unauthorized traffic from reaching data center servers.BackupsData is backed up daily and weekly, with master/slave replication for hot-swappable database backups. Backups are stored in separate Amazon data centers from the primary Klipfolio application, so they're recoverable even if the primary center is lost.Code testing and assessmentsWe test all code for security vulnerabilities before release and regularly scan our network and systems, including:
Application vulnerability threat assessments
Network vulnerability threat assessments
Selected penetration testing and code review
Security control framework review and testing
Security monitoringOur team monitors notifications from multiple sources and alerts from internal systems to identify and manage threats.