All data is secured in Amazon Web Services (AWS) datacenters with enterprise-grade physical and network security. Data can be stored in our US-, EU-, or Canada-based regions. Data is not travelling across the regions.
Data is encrypted at rest and in transit, and PII is protected with an additional layer of application encryption.
Credentially maintains separate networks for webservers and databases, detects and logs access to systems, and grants unique credentials for each employee and tool.
Our developers are proactive when it comes to security and use both DAST and SAST security scanning tools.
We work with some of the best external independent specialist firm to conduct a CREST-certified penetration testing that is based on the latest every year and an automated scan on a weekly basis.
All testing performed is based on the NIST SP 800-115 Technical Guide to Information SecurityTesting and Assessment, OWASP Web Security Testing Guide and the Penetration TestingExecution Standard frameworks.
Credentially adheres to industry-standard compliance frameworks. This ensures that our internal controls and processes meet and exceed requirements in securing customer data and the availability of our product infrastructure. Documentation of our compliance against global standards including certifications, attestations, and audit reports.
We ensure your employee records are kept securely and in a manner compliant with GDPR. We set up record keeping, provide audit tools and handle subject access requests by your data subjects (your staff).
You can review the exact security standards we use here and read our privacy policy.
If our EU and UK customers select our European environment, their datawill only be stored in London, UK.
Credentially puts in place a DPA (data processing agreement) with all customers, whereby Credentially commits to processing data transfers in accordance with GDPR’s Standard Contractual Clauses. In addition, we offer Customers control over where their data is stored.
You can also contact our Data Protection Officer at dpo@credentially.io
Fault-tolerant infrastructure ensures availability even during extreme demand.
Live uptime and subscription to system incident and downtime alerts are always available at https://status.credentially.io
Credentially provides a standard SLA to all it’s customers. It is available here
Please see our policies on the Terms and Policy