Security is our top priority.
We understand the importance of protecting your data and are committed to ensuring confidentiality and privacy. Data is encrypted, storage is secure, and access is strictly controlled.
This following guide highlights Anduin’s industry standard security features.
Anduin infrastructure and application are architected to achieve a high level of business continuity, which includes disaster recovery (DR) and high availability (HA).
Our DR solutions provide fully automated failover to a backup system so that our services can continue to operate without disruption. Customers’ data are continuously replicated across different availability zones on Amazon AWS cloud. In addition, all databases and document storage systems are backed up throughout the day.
Our HA solutions aim at offering 3 9’s uptime. We employ a multi-layered approach to achieve this HA goal: rapid scaling in response to workload, application resilience to user errors and infrastructure failures, data resilience to corruption, and infrastructure resilience to environmental failures (e.g., machine down, network disconnection).
Anduin enforces a strong authentication flow from user logins to every single API request: our servers verify if users are who they claim to be. We offer industry standards to achieve this goal:
As a multi-tenant platform, our system enforces a strict authorization flow to all data access points: users are restricted from accessing data when they don’t have the rights to do so.
Access rights are determined by a well-defined system of roles, for example, deal owner, deal participant, data room owner, and data room participant. This approach balances offering users flexible control of access rights to their data assets, while allowing strong enforcement of data accessing.
Our platform utilizes pre-authorized access tokens for secure and predefined actions, e.g., to e-sign, complete a task, or view a report, without logging in.
All data transmitted to the Anduin system from clients is encrypted using HTTPS and SSL. Our user data and critical infrastructure configurations are encrypted using AES 256-bit. All encryption keys are protected by an industry-grade secret management tool. The secret vault is protected by a two-man integrity policy. We have initiated the process to obtain a SOC 2 Type 1 certification of our security design, and subsequently a SOC 2 Type 2 certification of our operating security enforcement.
Anduin servers are protected behind firewalls to control both internal and external traffic. Our systems use virtual networks for isolation and protection. We are setting up regular network penetration testing to proactively detect potential threats.
Anduin may access customer data only for the purpose of providing a service, preventing or addressing technical problems, at a customer’s request in connection with customer support matters, or as may be required by law.
At Anduin we maintain the principle of least privilege for all customer data. Employees are given access only to data that is a minimum requirement to perform those operations. Where necessary, personal data are pseudonymized to protect data confidentiality.
Data access controls (such as separation of duties) are designed to prevent personnel from mishandling of data. These access controls are continually reviewed and updated, as necessary.
At Anduin, we maintain up-to-date operating systems across our network. Verified security patches are deployed as they’re released. We continuously monitor for both malicious and accidental incidents.
Anduin uses industry-standard encryption for SMTP communication channels through TLS. We enforce the legitimacy of the TLS certificates for email exchange.
All actions in the system are logged in an immutable audit trail accessible to system administrators. Anduin provides a suite of tools to search, filter, and report on these actions.
Anduin is compliant with the following:
We are actively working on obtaining: