Security
A written information security programme, physical and technical controls, disaster recovery tested annually, and a defined incident procedure.
What follows is a plain summary. The binding version is Security Practices, and where the two differ, that document governs.
A written programme
Koidra maintains a comprehensive written information security programme: policies, standards and procedures covering how customer data is processed and how the systems that handle it are secured. Subcontractors we engage are held to substantially similar levels.
Under that programme we implement physical, organisational and technical controls designed to keep customer data confidential and intact, and to protect it from anticipated threats, accidental loss, alteration and unlawful processing.
Disaster recovery, tested every year
We run a disaster recovery programme intended to restore service availability after a disaster. It commits to four specific things:
- Routine validation that retention copies of customer data are created, so lost or corrupted data can be recovered
- An inventory of every critical system, updated at least annually
- Annual review and update of the programme itself
- Annual testing to validate the procedures and confirm the service can actually be recovered
The annual test is the part that matters. A recovery plan nobody has exercised is a document, not a capability.
If something happens
If we become aware of confirmed unauthorised or unlawful access to customer data, we notify you promptly and take reasonable steps to limit the damage. Notifications go to your system administrators, which is why keeping their contact details current in the product is worth doing before you need it.
The document is specific about what does not count, and that specificity is deliberate rather than evasive. Port scans, failed logins, denial of service attempts and similar noise that never reaches customer data are not incidents, because a notification for every blocked probe would bury the one that matters. Nor is access that follows from a user’s own credentials being compromised or a user disclosing data themselves.
What to ask us during procurement
Security questionnaires are a normal part of buying software and we would rather answer yours directly than have you infer answers from a web page. Ask about hosting regions, subprocessors, access controls, retention periods, and anything your own policy requires.
Related: data ownership and uptime.
Also in trust
Send us your security questionnaire
We would rather answer your questions directly than have you infer the answers from a web page. Hosting regions, subprocessors, retention, access control: ask.
Talk to our team