The security of your data is of utmost importance to us. CASM is committed to protecting your information with multiple layers of security, including physical, network, and application-level controls. Below is an overview of the measures we have in place to safeguard your information.
Access to Your CASM Data
- Your account is protected by a unique username and password. No one can access your company data unless you explicitly grant them access by inviting them to your account.
- Each invited user is required to log in using their own secure credentials.
- To protect against unauthorised access, users are automatically logged out after a period of inactivity.
Hosting & Physical Security
- CASM operates in a managed hosting environment with robust physical security controls.
- The data centre is protected by 24/7 armed security personnel and continuous CCTV surveillance.
- Physical infrastructure is housed in access-controlled facilities, and only authorised personnel are allowed entry.
- All systems are monitored to ensure hardware and environmental conditions are stable, with alerts for critical events.
Network & System Security
- CASM runs behind an industry-standard firewall that blocks unauthorised access and filters incoming traffic to allow only legitimate activity.
- Intrusion detection systems (IDS) are in place to monitor and log suspicious activity, including service attacks and injection attempts.
- System logs and firewall alerts are reviewed regularly to detect any signs of intrusion or anomalies.
- All systems are routinely scanned and patched to identify and mitigate vulnerabilities.
Monitoring & Availability
- CASM infrastructure is monitored around the clock using automated tools to ensure server uptime and performance.
- System-level alerts allow for rapid response to any hardware, software, or network issues — reducing potential downtime and service disruption.
- Monitoring helps ensure the platform remains resilient and any failures are addressed quickly.
Data Backup & Redundancy
- Your CASM data is backed up daily and stored in secure offsite locations.
- Backup retention is maintained for a rolling two-week period.
- Redundant storage ensures multiple points of failure are accommodated, reducing the risk of data loss.
Data Encryption & SSL Security
- All data transmitted between your browser and CASM is encrypted using SSL (Secure Sockets Layer).
- CASM uses a fully authenticated security certificate issued by a reputable certificate authority.
- Data is encrypted with up to 256-bit encryption (depending on your browser), ensuring that information remains protected during transmission.
Ongoing Security Practices
- CASM’s security protocols are regularly reviewed and updated to align with evolving best practices.
- System components and policies are audited periodically to identify potential security gaps or new threats.
- We maintain a proactive approach to risk mitigation and respond swiftly to any identified vulnerabilities.