Security & Compliance

Your CISO Will Read This Before Your CTO Signs Anything

The text below is written from the perspective of your CISO. It covers how we grant access to your systems, treat your data, build software securely, respond to incidents, stay compliant with regulations, and what documentation we provide for a security review.

Mode of action

We operate under the assumption that your data never leaves your perimeter

For the majority of enterprise engagements, we deploy into your cloud account, under your identity provider, and within your network perimeter. Your data does not traverse our infrastructure and our access is always scoped, temporary, and auditable by your systems.

In cases where this is not possible, that restriction is called out clearly in the architecture documentation and requires written approval prior to development.

Authorization

How We Operate Within Your Systems

Access controls are a critical security discipline at Vortex Web Innovate, and we employ a number of restrictions to limit our potential attack surface and impact.

All individual access is granted through named accounts, and shared credentials are not permitted. All accounts have multifactor authentication enabled and utilize your identity provider for additional authorization. The principle of least privilege is the default for our production access, which is always task-scoped, time-bound, and deleted at the end of our support.

We connect to your systems via your identity provider, and our access is logged in your audit trails when available.

Access is reviewed at every point of engagement and is revoked when an individual exits it, within the window your agreement sets. We also require a formal offboarding checklist to be completed on a per-employee basis, with evidence provided upon request.

Data processing

How We Treat Your Data

Production data is not taken out of production, and we use either synthetic or anonymized data sets for development and testing
Data is masked and minimized for use cases that require use of production data
TLS 1.2+ encrypted in transit, and encrypted at rest with your cloud provider's keys or your KMS (if externally managed)
Secrets are managed in a secrets vault with regular rotation and are never committed to source control, tickets, or other platforms. PII and PHI data is handled according to your industry's requirements and is noted for each engagement.
Data retention and deletion schedules are set in accordance with the DPA and sub-processor requirements.
How We Secure Our Software Development

How We Create

Security is designed into our development lifecycle, and not as an afterthought
All production merges require peer approval
All pipelines have static analysis, dependency, and secret scans on every commit
Infrastructure as code is used and production is never manually manipulated
Environments are isolated and we do not share credentials between them. Everything is signed, versioned, and built in a repeatable and auditable way. All artifacts are versioned and previous versions are retained and deployable at any point
Third-party pentesting is done in hardening phases, and remediation is handled separately
Compliance

Compliance

The security practices of Vortex Web Innovate are auditable against a wide variety of compliance needs relevant to enterprise engagements.

SOC 2 Compliance

Our technical controls and procedures are created around the Trust Services Criteria, and we employ relevant procedures depending on the scope of your engagement

ISO 27001 Compliance

Our information security management system is built around ISO 27001 standards with relevant procedures depending on your requirements, including policies around access controls, inventory, incident management, and supplier management controls among others.

GDPR Compliance

We are able to enter into a DPA, maintain a sub-processor list, process data subject requests, and have solutions deployed in EU regions for data residency.

HIPAA Compliance

A Business Associate Agreement is available for HIPAA covered entities, and our technical procedures are built around the requirements of the Security Rule.

PCI DSS Compliance

Where applicable, cardholder data is out of scope for our systems by using tokenized payment processors

Insurance

We maintain cyber liability and professional indemnity insurance, and we are able to provide a certificate of insurance upon request.

Business Stability

Continuity of Operations and Incident Response

We are able to provide documented playbooks at all times that reflect our policies and procedures for the following:

Incident Escalation

An escalation path is established at the beginning of an engagement that includes a specific individual at Vortex Web Innovate that can be contacted at all times

Client Notification

You will be notified of any incident that affects your data or systems, within the notification window your agreement sets, from the point we discover it. We perform a post-incident review that is shared with you in writing, if possible

Key person insurance

We are able to provide key person insurance, which is reflected in our documented procedures that are available for review

Retention and access

Code, infrastructure, and documentation are retained in a way that is available for review at all times, whether in your repositories or through shared access
Vendor Setup

What We Provide For Your Security Review

We are happy to provide the following information as part of our security package. Please fill out our security questionnaire, and we will endeavor to respond within the turnaround named in the package.

Security Questionnaire response (SIG/CAIQ or other format as needed)
Infosec policy summary
Sub processor list
Certificate of insurance
MSA, NDA, and DPA (Vortex Web Innovate standard or as executed against your requirements)
Architecture and data flow diagram
Named security contact
SOC 2 report or other relevant audit, under NDA if available

Designed for Enterprise Security Reviews

Security should not be a gating function for enterprise engagements. By thinking about access, data usage, development security, compliance, continuity of operations, and documentation from the beginning of an engagement, teams can be confident that risk is appropriately managed by default, rather than as an afterthought.

Request the Security Package

Send us your security questionnaire

We'd rather answer it now than discover a blocker in month three.