Data Protection

Data Protection

Last updated at: May 6, 2020

Keeping your data private and secure is paramount. We protect your data from malicious actors and from the more common, honest human mistakes that your employees might make while accessing your data.

Cloud Infrastructure

Hippobyte is built on top of AWS. Cloud security at AWS is the highest priority. As an AWS customer, we and you benefit from a data center and network architecture built to meet the requirements of the most security-sensitive organizations.

Data Encryption

Your data is encrypted throughout its entire lifecycle while within the Hippobyte Platform. Your data is your own, we do not persist, store, or analyze your data unless you’ve specifically authorized us to do so.

All data moving through the Hippobyte Platform is considered data in motion, or data in transit or data in flight. All data in motion is encrypted using 256-bit Advanced Encryption Standard, the AES-256 GCM algorithm — the same level of data security required by the Sarbanes-Oxley Act, the Gramm-Leach-Bliley Act and the Health Insurance Portability and Accountability Act (HIPAA).

Passwords

Hippobyte takes a multi-level approach to storing all sign-in credentials. Protection begins with “hashing” passwords, a common approach for taking passwords of varied lengths and turning them into cryptic, fixed-length passwords for storage. Hippobyte also “salts” customer passwords, or adds extra data that is unique to every user to employ an additional level of password protection.

Key Management

Hippobyte pays special attention to the key lifecycle, as well as the allocation of roles within the key management infrastructure. Hippobyte’s key management policy employs a set of rules designed to secure the key lifecycle using a combination of security mechanisms that include strong password, routine revocation of keying, key backup and recovery.

Disaster Recovery and Continuity Plan

Hippobyte maintains a robust disaster recovery program at all data centers, which are distributed across the United States. A high-speed encrypted VPN tunnel connects the data centers and supports traffic shifting or traffic failover. To prevent data loss, Hippobyte performs ongoing data replication and backup within each data center to a local disaster recovery site, and to the hot standby data center.

Disaster Recovery and Continuity Testing

Hippobyte has both a disaster recovery plan and a business continuity plan in place, and regularly tests them to ensure they are working properly. The disaster recovery plan includes a comprehensive and established series of actions to take before, during and after a disruptive event. It includes an alternative processing site and an approach to return to the primary processing site as quickly as possible. The business continuity plan includes a comprehensive approach to quickly restore computer systems upon the event of any service interruption.

Hippobyte
© 2015 - 2021 Hippobyte, Inc. All rights reserved.