We operate under the assumption that your data never leaves your perimeter
For the majority of enterprise engagements, we deploy into your cloud account, under your identity provider, and within your network perimeter. Your data does not traverse our infrastructure and our access is always scoped, temporary, and auditable by your systems.
In cases where this is not possible, that restriction is called out clearly in the architecture documentation and requires written approval prior to development.
How We Operate Within Your Systems
Access controls are a critical security discipline at Vortex Web Innovate, and we employ a number of restrictions to limit our potential attack surface and impact.
All individual access is granted through named accounts, and shared credentials are not permitted. All accounts have multifactor authentication enabled and utilize your identity provider for additional authorization. The principle of least privilege is the default for our production access, which is always task-scoped, time-bound, and deleted at the end of our support.
We connect to your systems via your identity provider, and our access is logged in your audit trails when available.
Access is reviewed at every point of engagement and is revoked when an individual exits it, within the window your agreement sets. We also require a formal offboarding checklist to be completed on a per-employee basis, with evidence provided upon request.
How We Treat Your Data
How We Create
Compliance
The security practices of Vortex Web Innovate are auditable against a wide variety of compliance needs relevant to enterprise engagements.
SOC 2 Compliance
Our technical controls and procedures are created around the Trust Services Criteria, and we employ relevant procedures depending on the scope of your engagement
ISO 27001 Compliance
Our information security management system is built around ISO 27001 standards with relevant procedures depending on your requirements, including policies around access controls, inventory, incident management, and supplier management controls among others.
GDPR Compliance
We are able to enter into a DPA, maintain a sub-processor list, process data subject requests, and have solutions deployed in EU regions for data residency.
HIPAA Compliance
A Business Associate Agreement is available for HIPAA covered entities, and our technical procedures are built around the requirements of the Security Rule.
PCI DSS Compliance
Where applicable, cardholder data is out of scope for our systems by using tokenized payment processors
Insurance
We maintain cyber liability and professional indemnity insurance, and we are able to provide a certificate of insurance upon request.
Continuity of Operations and Incident Response
We are able to provide documented playbooks at all times that reflect our policies and procedures for the following:
Incident Escalation
An escalation path is established at the beginning of an engagement that includes a specific individual at Vortex Web Innovate that can be contacted at all timesClient Notification
You will be notified of any incident that affects your data or systems, within the notification window your agreement sets, from the point we discover it. We perform a post-incident review that is shared with you in writing, if possibleKey person insurance
We are able to provide key person insurance, which is reflected in our documented procedures that are available for reviewRetention and access
Code, infrastructure, and documentation are retained in a way that is available for review at all times, whether in your repositories or through shared accessWhat We Provide For Your Security Review
We are happy to provide the following information as part of our security package. Please fill out our security questionnaire, and we will endeavor to respond within the turnaround named in the package.
Designed for Enterprise Security Reviews
Security should not be a gating function for enterprise engagements. By thinking about access, data usage, development security, compliance, continuity of operations, and documentation from the beginning of an engagement, teams can be confident that risk is appropriately managed by default, rather than as an afterthought.
Request the Security PackageSend us your security questionnaire
We'd rather answer it now than discover a blocker in month three.