Security

iDONATEpro Security

iDONATEpro provides Software as a Service (SaaS) products to users nationwide. Security is a key component in our offerings, and is reflected in our people, process, and products.

Customer controls for security

The biggest threats to your security come from within your organization.

  • Choose unique, strong passwords and protect them.
  • Don't share sign-in credentials across people. An AI tool may use a dedicated authorized User login as described under Identity and Access control.
  • Manage users' permissions.
  • Use the latest browser versions, mobile OS and updated mobile applications to ensure they are patched against vulnerabilities and to use latest security features.
  • Be aware of phishing and malware threats by looking out for unfamiliar emails, websites, and links that may exploit your sensitive information by impersonating iDONATEpro or other services you trust.

Organizational Security

We have an Information Security Management System (ISMS) in place which takes into account our security objectives and the risks and mitigations concerning all the interested parties. We employ strict policies and procedures encompassing the security, availability, processing, integrity, and confidentiality of customer data.

Infrastructure security

Network security

Our network security and monitoring techniques are designed to provide multiple layers of protection and defense. We use firewalls to prevent our network from unauthorized access and undesirable traffic. Our systems are segmented into separate networks to protect sensitive data. Systems supporting testing and development activities are hosted in a separate network from systems supporting iDONATEpro's production infrastructure.

We monitor firewall access with a strict, regular schedule. A network engineer reviews all changes made to the firewall every day. Additionally, these changes are reviewed once in every six months to update and revise the rules. Our dedicated Network Operations Center team monitors the infrastructure and applications for any discrepancies or suspicious activities.

Network redundancy

All the components of our platform are redundant. We use a distributed grid architecture to shield our system and services from the effects of possible server failures. If there's a server failure, users can carry on as usual because their data and iDONATEpro services will still be available to them. We additionally use multiple switches, routers, and security gateways to ensure device-level redundancy.

DDoS prevention

We use technologies from well-established and trustworthy service providers to prevent DDoS attacks on our servers. These technologies offer multiple DDoS mitigation capabilities to prevent disruptions caused by bad traffic, while allowing good traffic through.

Server hardening

All servers provisioned for development and testing activities are hardened (by disabling unused ports and accounts, removing default passwords, etc.). The base Operating System (OS) image has server hardening built into it.

Intrusion detection and prevention

Our intrusion detection mechanism takes note of host-based signals on individual devices and network-based signals from monitoring points within our servers. Administrative access, use of privileged commands, and system calls on all servers in our production network are logged. At the application layer, we have our proprietary WAF which operates on both whitelist and blacklist rules.

Data security

Secure by design

Every change and new feature is governed by a change management policy to ensure all application changes are authorised before implementation into production. Our Software Development Life Cycle (SDLC) mandates adherence to secure coding guidelines. The application follows OWASP guidance and includes protections against threats such as SQL injection, Cross site scripting and application layer DOS attacks.

Data isolation

Our framework distributes and maintains the cloud space for our customers. Each customer's service data is logically separated from other customers' data using a set of secure protocols in the framework. The service data is stored on our servers when you use our services. Your data is owned by you, and not by iDONATEpro. We do not share this data with any third-party without your consent.

Encryption

In transit: All customer data transmitted to our servers over public networks is protected using strong encryption protocols. We mandate all connections to our servers use Transport Layer Security (TLS 1.2/1.3) encryption with strong ciphers, for all connections including web access, API access, our mobile apps, and IMAP/POP/SMTP email client access. We have full support for Perfect Forward Secrecy (PFS) with our encrypted connections, and we have enabled HTTP Strict Transport Security header (HSTS) to all our web connections.

At rest: Sensitive customer data at rest is encrypted using 256-bit Advanced Encryption Standard (AES). We own and maintain the keys using our in-house Key Management Service (KMS). We provide additional layers of security by encrypting the data encryption keys using master keys. The master keys and data encryption keys are physically separated and stored in different servers with limited access.

Data retention and disposal

We hold the data in your account as long as you choose to use iDONATEpro Services. Once you terminate your iDONATEpro account, your data will get deleted from the active database during the next clean-up that occurs once every 6 months. The data deleted from the active database will be deleted from backups after 3 months. In case of your unpaid account being inactive for a continuous period of 120 days, we reserve the right to terminate it after giving you prior notice and option to back-up your data.

Identity and Access control

iDONATEpro offers single sign-on (SSO) that lets users access multiple services using the same sign-in page and authentication credentials. When you sign in to any iDONATEpro service, it happens only through our integrated Identity and Access Management (IAM) service. We also support SAML for single sign-on that makes it possible for customers to integrate their company's identity provider like LDAP, ADFS when they login to iDONATEpro services.

We employ technical access controls and internal policies to prohibit employees from arbitrarily accessing user data. We adhere to the principles of least privilege and role-based permissions. Access to production environments is maintained by a central directory and authenticated using a combination of strong passwords, two-factor authentication, and passphrase-protected SSH keys.

Customers may use their own AI tools to sign in only through the same authenticated User login, with the same permissions as that User. There is no back-end AI or API access to customer data. We recommend that customers give each AI tool a dedicated User login so its activity is separated and can be revoked independently.

Operational security

Logging and Monitoring

We monitor and analyse information gathered from services, internal traffic in our network, and usage of devices and terminals. We record this information in the form of event logs, audit logs, fault logs, administrator logs, and operator logs.

Vulnerability management

We have a dedicated vulnerability management process that actively scans for security threats using a combination of certified third-party scanning tools and in-house tools, and with automated and manual penetration testing efforts.

Malware and spam protection

We scan all user files using our automated scanning system that’s designed to stop malware from being spread through iDONATEpro's ecosystem. iDONATEpro supports Domain-based Message Authentication, Reporting, and Conformance (DMARC) as a way to prevent spam.

Backup

We run incremental backups every day and weekly full backups of our databases. Backup data is stored in the same location and encrypted. All backed up data are retained for a period of three months.

Disaster recovery and business continuity

Application data is stored on resilient storage that is replicated across data centers. Data in the primary DC is replicated in the secondary in near real time. In case of failure of the primary DC, secondary DC takes over and the operations are carried on smoothly with minimal or no loss of time.

Vendor and Third-party supplier management

We evaluate and qualify our vendors based on our vendor management policy. We onboard new vendors after understanding their processes for delivering us service, and performing risk assessments.

Contact

iDONATEpro
2033 San Elijo Avenue #203, Cardiff by the Sea, CA 92007
(800) 397-9301
Support@iDONATEpro.com