How Do We Keep Your Data Safe?
All SureDone accounts use SSL-encrypted connections by default — the same level of security used by online banks. You never send or receive sensitive information in plain-text. Additionally, industry-standard physical and remote security is administered at datacenter facilities.
We Focus on Your Privacy
SureDone cares deeply about protecting the privacy of the data entrusted to us by our customers. This is one of the core values at the heart of our business. Please review our
Privacy Policy for specific details.
Why SureDone will Be There When You Need It
SureDone achieves an average 99.9% uptime. Here are a few things we do to ensure we stay available for you whenever you need to access your information:
- Network connectivity is provided by multiple top carriers.
- All data is protected by hardware RAID over multiple data storage units.
- Critical servers have redundant power supplies.
- Critical components are deployed in (at least) redundant pairs.
Our Data Retention Policy
We take our role as custodian of your data extremely seriously. We have multiple backup systems in place to protect your data, governed by the following policies:
- All backups are replicated to at least 2 physical datacenters.
- All backup systems are tested biweekly.
- Backups occur once daily at a minimum, with many occurring twice daily.
- Database backups are retained for 180 days.
- Application logs (for assisting SureDone Support cases) are retained for 12 days.
Industry Standard Security
SureDone systems and processes adhere to industry best practices in security, including the following:
- Encrypted inter-server and inter-datacenter communication.
- Sensitive data encryption in the databases.
- Tightly firewalled and monitored servers.
- Strictly controlled access to servers or customer data.
- Immutable audit trail for support-related data access.
Responsible Security Disclosure
SureDone has an engaged developer community and we value the role played by third parties in Internet security. Our customers trust us with their data and we take this trust extremely seriously. The following process is in place for any person or organization to report vulnerabilities in the SureDone service:
- Email a complete description of the issue to support@suredone.com. Include code samples and as much detail as possible.
- The SureDone security team will acknowledge receipt of the email promptly and investigate.
- Most reports will take less than 24 hours to investigate and determine a course of action.
- Be responsible and retain the private nature of this disclosure until the SureDone security team has responded to your submission with a timeline of any mitigation underway.
- SureDone does not pursue any action against parties who disclose issues through this process.
- SureDone does not compensate disclosing parties for submissions.