Trust Center - Ethyca

Ethyca

Privacy compliance automated

To grow your business, you need to prove your customers can trust you with their data.

Ethyca simplifies trust - so you can focus on business.

Controls

Updated 33 minutes ago

Infrastructure security

Control Status
Infrastructure performance monitored
An infrastructure monitoring tool is utilized to monitor systems, infrastructure, and performance and generates alerts when specific predefined thresholds are met.
Network and system hardening standards maintained
The company's network and system hardening standards are documented, based on industry best practices, and reviewed at least annually.
Log management utilized
The company utilizes a log management tool to identify events that may have a potential impact on the company's ability to achieve its security objectives.
Access control procedures established
The company's access control policy documents the requirements for the following access control functions:
- adding new users;
- modifying users; and/or
- removing an existing user's access.
Encryption key access restricted
The company restricts privileged access to encryption keys to authorized users with a business need.
Network segmentation implemented
The company's network is segmented to prevent unauthorized access to customer data.
Access requests required
The company ensures that user access to in-scope system components is based on job role and function or requires a documented access request form and manager approval prior to access being provisioned.
Remote access MFA enforced
The company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.
Data encryption utilized
The company's datastores housing sensitive customer data are encrypted at rest.
Production network access restricted
The company restricts privileged access to the production network to authorized users with a business need.

Organizational security

Control Status
Employee background checks performed
The company performs background checks on new employees, where allowed by law.
Employee Handbook acknowledged by employees
The company’s employees acknowledge the
employee handbook at the time of hire. The handbook contains guidance on employee behavior and conduct.
Data retention procedures established
The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data.
Anti-malware technology utilized
The company deploys anti-malware technology to environments commonly susceptible to malicious attacks and configures this to be updated routinely, logged, and installed on all relevant systems.
Vulnerability and system monitoring procedures established
The company's formal policies outline the requirements for the following functions related to IT / Engineering:
- vulnerability management;
- system monitoring.

Product security

Control Status
Control self-assessments conducted
The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings.
Penetration testing performed
The company's penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs.

Internal security procedures

Control Status
SOC 2 - System Description
Complete a description of your system for Section III of the audit report
Organization structure documented
The company maintains an organizational chart that describes the organizational structure and reporting lines.
Roles and responsibilities specified
Roles and responsibilities for the design, development, implementation, operation, maintenance, and monitoring of information security controls are formally assigned in the Roles and Responsibilities policy.
Cybersecurity insurance maintained
The company maintains cybersecurity insurance to mitigate the financial impact of business disruptions.
Security policies established and reviewed
The company's information security policies and procedures are documented and reviewed at least annually.
System changes communicated
The company communicates system changes to authorized internal users.
Incident response policies established
The company has security and privacy incident response policies and procedures that are documented and communicated to authorized users.
Risk management program established
The company has a documented risk management program in place that includes guidance on the identification of potential threats, rating the significance of the risks associated with the identified threats, and mitigation strategies for those risks.
Risks assessments performed
The company's risk assessments are performed at least annually. As part of this process, threats and changes (environmental, regulatory, and technological) to service commitments are identified and the risks are formally assessed. The risk assessment includes a consideration of the potential for fraud and how fraud may impact the achievement of objectives.
Continuity and Disaster Recovery plans established
The company has Business Continuity and Disaster Recovery Plans in place that outline communication plans in order to maintain information security continuity in the event of the unavailability of key personnel.

Data and privacy

Control Status
Data classification policy established
The company has a data classification policy in place to help ensure that confidential data is properly secured and restricted to authorized personnel.
Customer data deleted upon leaving
The company purges or removes customer data containing confidential information from the application environment, in accordance with best practices, when customers leave the service.

Vanta connects to a company's core systems to continuously monitor these controls.