Security Policy
introduction at sparklayer, we understand the responsibility we bear in managing customer data, and we are dedicated to ensuring its safety and security we maintain a comprehensive set of security policies that continually evolve and adapt as we work diligently to safeguard your information the protection of customer data is of utmost importance to sparklayer, and we prioritise a security first approach in the design of our software data centre security to uphold our commitment to security, we host our systems on cloud service providers that align with our stringent security standards currently, we use the google cloud platform, which reflects our values and provides robust physical security measures for further information on their physical security practices, please visit cloud google com/security https //cloud google com/security encryption we employ encryption at rest, at work, and in transit to ensure the protection of customer data all our encryption processes adhere to the best practices provided by google, our trusted encryption provider this means that all data transmitted between you and our services is encrypted using transport layer security (tls), and all data stored within google is encrypted for maximum security two factor authentication and security keys we require employees to use two factor authentication (2fa) whenever possible for the services we use as a business we provide employees with security keys (fido u2f) and prefer their use over time based one time passwords and text message based two factor authentication solutions whenever feasible, we enforce the use of 2fa through the security keys this ensures that even if a password is compromised, unauthorised access is prevented as cyber attackers would also need physical possession of our hardware role based access access to sparklayer systems is granted to employees on a need to know basis, limiting the scope of potential compromise and ensuring security is maintained internal security training and policies sparklayer maintains a comprehensive set of internal security policies that all employees are required to understand and adhere to these policies cover various aspects, including the use of strong passwords, full disk encryption of business computers, email policies, limitations on data use and storage, and more security minded software development practices we adhere to the principle of "security by design" in our software development practices, integrating security considerations throughout the entire software development life cycle this includes implementing secure coding standards to prevent common vulnerabilities, conducting code reviews before deployment to production, and employing automated testing to identify potential security weaknesses our staff undergo regular training to ensure they remain up to date with the latest practices recommended by the open web application security project (owasp) up to date software to mitigate known vulnerabilities, sparklayer ensures the use of up to date versions of operating systems, kernels, packages, and libraries we prioritise automation as much as possible, using our ci/cd platform, github, to streamline the process of keeping our software stack current and secure in our production environment backups for all systems containing customer data, we have implemented automated daily backups additionally, we enable point in time recovery wherever possible we rely on our trusted google cloud provider to handle backup operations, ensuring that backups are encrypted and stored in three separate data centres review and update regular review and testing are essential for the effectiveness of any policy at sparklayer, we conduct thorough policy reviews and testing twice a year this enables us to identify areas for improvement and promptly implement necessary actions to enhance our security and policies sparklayer remains committed to the highest standards of data security, continuously improving our practices to safeguard customer information