Program overview
DataSync’s security program is built on layered technical controls, rigorous governance, and third-party audits. This policy summarizes the safeguards that protect customer data and the responsibilities shared between DataSync and customers.
Governance
- Frameworks: DataSync is SOC 2 Type II audited annually and maintains HIPAA controls for applicable customers.
- Policies: Security, access, change management, and incident response policies are reviewed at least annually.
- Training: All employees complete security, privacy, and phishing training during onboarding and annually thereafter.
Technical controls
- Encryption: Customer data is encrypted at rest using AES-256 and in transit using TLS 1.2+. AS2 and SFTP connections enforce mutual authentication.
- Access management: Single sign-on (SSO), SCIM provisioning, least-privilege roles, and time-bound access approvals are enforced for internal tools and production systems.
- Monitoring: Logs, metrics, and traces are streamed to a central SIEM with automated alerting, anomaly detection, and on-call escalation.
Application security
- Secure development lifecycle practices include peer reviews, automated testing, dependency scanning, and regular penetration tests by independent firms.
- All changes to production follow change-control procedures with rollback plans.
Incident response
- DataSync maintains a 24/7 incident response team with documented playbooks.
- Customers are notified promptly if their data is impacted, including details, remediation steps, and follow-up actions.
Business continuity
- The platform operates in active-active regions with automated failover, backups, and disaster recovery drills.
- Recovery point objective (RPO) is < 15 minutes; recovery time objective (RTO) is < 1 hour for critical services.
Customer responsibilities
- Configure access controls (SSO, RBAC) according to organizational policies.
- Keep contact information and escalation paths current.
- Use supported encryption configurations for partner connections.
Contact
For security inquiries or to request additional documentation, email security@datasync.com.