Effective date
The Processor maintains and implements the following technical and organizational security measures to protect Personal Data against unauthorized access, destruction, loss, alteration, or disclosure:
1. Data Encryption and Communication Security
- Encryption in Transit: All network communication between users, viewers, and the LHM platform is encrypted using standard Transport Layer Security (TLS 1.2 or higher / HTTPS / WSS).
- Encryption at Rest: Personal Data stored in relational and non-relational databases, object storage, and backups is encrypted using industry-standard AES-256 encryption keys.
2. Access Controls and Identity Management
- Logical Access Control: Access to production infrastructure is governed by strict Role-Based Access Control (RBAC) adhering to the Principle of Least Privilege.
- Multi-Factor Authentication (MFA): We use MFA/2FA.
- Password Policy: Mandatory strong password.
3. Physical and Infrastructure Security
- Data Center Security: Production workloads are hosted exclusively in tier-3 equivalent, SOC 2 / ISO 27001 certified cloud infrastructure providers located within the European Union.
- Physical Access Restrictions: Physical access to data centers is protected via AWS Amazon. You can find more information here: https://aws.amazon.com/trust-center/data-center/our-controls/
4. Availability, Backups, and Resilience
- Automated Backups: Automated database backups are generated.
- Disaster Recovery: We have disaster recovery plans.
- High Availability: High availability architecture.
5. System Integrity and Vulnerability Management
- Vulnerability Monitoring: Regular automated scanning of dependencies and infrastructure for known security vulnerabilities (CVEs).
- Patch Management: Prompt deployment of security patches and updates across operating systems, containers, and applications.
- Log Management: Audit logging of administrative actions, system events, and authentication attempts monitored for suspicious activity.
6. Organizational Security and Confidentiality
- Employee Confidentiality: All employees and independent contractors authorized to access Personal Data sign binding confidentiality agreements.
- Security Awareness: Regular security training provided to technical staff regarding data privacy, phishing defense, and secure coding practices.