Last Update 15th February 2024
1. Purpose.
This Security Policy / Overview describes Scalefaster's security program and technical and organizational security controls to protect (a) Customer Data from unauthorized use, access, disclosure, or theft and (b) the Services. As security threats shift and evolve, Scalefaster continues to update its security program and strategy to help protect Customer Data and the Services. As such, Scalefaster reserves the right to update this Security Overview from time to time.
2. About Security Organization and Program.
Scalefaster maintains a risk-based assessment security program. The framework for Scalefaster's security program includes administrative, organizational, technical, and physical safeguards reasonably designed to protect the Services and confidentiality, integrity, and availability of Customer Data. Scalefaster’s security program is intended to be appropriate to the nature of the Services and the size and complexity of Scalefaster’s business operations.
3. Confidentiality
Scalefaster has controls in place to maintain the confidentiality of Customer Data. All Scalefaster's employees and contract personnel are bound by Scalefaster's internal policies regarding maintaining the confidentiality of Customer Data and are contractually obligated to comply with these obligations.
4.0 Employee Training.
Scalefaster's employees /contractors must complete a security and privacy training which covers Scalefaster's security policies, security best practices, and privacy principles. Employees on a leave of absence may have additional time to complete this training.
5.1 The core principles of our training is:
Architecture and Data Segregation
6.1 The platform for the Scalefaster's Services is hosted by Amazon Web Services (“AWS”) and Google Firebase.
The AWS data center infrastructure used in providing the Scalefaster services is located in the United States and United Kingdom. Additional information about security provided by AWS is available at https://aws.amazon.com/security and https://aws.amazon.com/whitepapers/overview-of-security-processes.
The Google Firebase infrastructure used in providing Scalefaster services is located in the United Kingdom and United States. Additional information about security provided by Google Firebease is available at https://firebase.google.com/support/privacy
6.2 Services. For the delivery of Services, all network access between production hosts is restricted, using firewalls to allow only authorized services to interact in the production network. Firewalls are in use to manage network segregation between different security zones in the production and corporate environments. Firewall rules are reviewed regularly. The Scalefaster's server architecture are designed and built to identify and allow access only to and from authorized customers. These controls prevent other customers from having access to Customer Data.
9.1 Provisioning Access. To minimize the risk of data exposure, Scalefaster follows the principles of least privilege through a team-based-access-control model when provisioning system access. Scalefaster personnel are authorized to access Customer Data based on their job function, role and responsibilities, and such access requires approval of the employee’s manager. Access rights to production environments are reviewed at least semi-annually. An employee’s access to Customer Data is promptly removed upon termination of their employment. Before an engineer is granted access to the production environment, access must be approved by management and the engineer is required to complete internal trainings for such access including trainings on the relevant team’s systems.
9.2 Password Controls. Scalefaster current policy for employee password management follows the NIST 800-63B guidance, and as such, our policy is to use longer passwords, with multi-factor authentication but not require special characters or frequent changes. Â
10 Discovery, Investigation, and Notification of a Security Incident. Scalefaster's will promptly investigate a Security Incident upon discovery. To the extent permitted by applicable law, Scalefaster will notify Customer of a Security Incident in accordance with the Data Protection Act. Security Incident notifications will be provided to the Customer via email to the email address designated by Customer in its account.
11 Resilience and Service Continuity. The Services use a variety of tools and mechanisms to achieve high availability and resiliency. Scalefaster also leverages specialized tools that monitor server performance, data, and traffic load capacity within each availability zone and colocation data center. If suboptimal server performance or overloaded capacity is detected on a server within an availability zone or colocation data center, Scalefaster aim to act promptly on these issues.
12 Backups and Recovery. Scalefaster performs regular backups of Customer Data, which is hosted on AWS’s data center infrastructure and Google Firebease. Customer Data that is backed up is retained redundantly across multiple availability zones and encrypted in transit and at rest using Advanced Encryption Standard (AES-256).
Running a sales team does not need to feel like an uphill battle, let AIÂ do the heavy lifting and supplement your team with hot prequalified callbacks and live transfers.