Security Statement

From Displayr
Jump to navigation Jump to search
  1. Authors of Displayr documents are required to have a unique user name and password that must be entered when a user first logs on.
  2. Passwords are stored using one-way encryption.
  3. "Cookies" are used to store information about users inside each user's web browser. The cookies do not include either the username or password of the user.
  4. Secure Sockets Layer (SSL) technology protects user information and uploaded data. This uses both server authentication and data encryption, ensuring that user data is safe, secure, and available only to authorized persons.
  5. User data uploaded to a dashboard, and our backups of this data are encrypted at rest.
  6. Passwords and credit card information are always sent over secure 128-bit encrypted SSL connections.
  7. Our procedures for managing payments and account information are PCI-DSS compliant.
  8. Credit card information is not processed, stored or transmitted on our servers. It is handled directly by third-party payment processors who are PCI-DSS compliant.
  9. Displayr runs in data centers managed and operated by Microsoft. These geographically dispersed data centers comply with key industry standards, such as ISO/IEC 27001:2013, for security and reliability. More information is available from Microsoft.
  10. The latest patches are automatically applied to our public-facing servers.
  11. Security policies and software restrictions are in place to:
    1. Prevent unauthorised persons from gaining access to our systems and underlying data.
    2. Limit access of authorised persons to only the data they require in the course of their role.
    3. Ensure only specially authorised persons are able to modify access rights to our systems.
    4. Protect against the accidental deletion of important data.
  12. Procedures are in place to ensure:
    1. Data storage mediums are destroyed or wiped before a system is disposed of.
    2. All new employees are made aware of our security policies and their relevant responsibilities.
    3. All employees leaving the company have their access rights immediately revoked in our systems.

Scanning

A penetration test is conducted annually against https://app.displayr.com/ by a trusted third-party using methodologies built on internationally recognized standards.

To supplement this annual test, https://app.displayr.com/ is also scanned quarterly by a third-party Approved Scanning Vendor (ASV) according to Payment Card Industry Data Security Standards (PCI DSS).

Reporting vulnerabilities

Vulnerabilities should be reported to security@displayr.com, this address is monitored by our developers.

What we do if there is a security breach

  • Attempt to notify affected users electronically within a timely manner.
  • Review our policies and procedures to mitigate the risk and limit the effect of a similar breach in future.

See also

Security and R contains information about the security of R calculations.

Last Modified: 8 May 2020