Data Encryption
Encryption at Rest: All data stored in our PostgreSQL database on the Google Cloud Platform is encrypted using industry-leading algorithms.
Encryption in Transit: Data transmitted between users, servers, and third-party providers is encrypted with Transport Layer Security (TLS).
Access Controls
User Account Security: User passwords are hashed and salted. Additionally, OAuth credentialing is used to access by Gmail and Office 365 email accounts.
Two-Factor Authentication (2FA): SMS-based adds an extra layer of security.
SAML-based Single Sign-On (SSO): We support SAML-based SSO, and OKTA allowing users to access 4Degrees with their existing enterprise credentials.
Compliance
GDPR Compliance: We adhere to the General Data Protection Regulation (GDPR) requirements, ensuring that all personal data is collected, processed, and stored in compliance with EU regulations.
CCPA Compliance: We comply with the California Consumer Privacy Act (CCPA).
CASA Tier 2: We have achieved CASA Tier 2 verification, ensuring rigorous security standards through independent assessment and validation.
Employee Training, Access and Security Audits
Employee Access Controls: Access to user data is restricted and based on the principle of least privilege.
Regular Training: Our employees undergo regular training on security best practices.
Annual Security Audits: We undergo comprehensive 3rd-party security audits to ensure our systems and practices remain secure.