Architecture
Our platform is hosted by Amazon Web Services. We use a variety of services including EC2, S3, RDS, CloudFront, Elastic Beanstalk, Comprehend and GuardDuty.
The platform is served over TLS1.2. Sensitive data is hashed using SHA256. Passwords are hashed using Bcrypt.
We mandate strict permissions and access management for developers, with highly limited database access. Keys are cycled every sixty days. ‘Super Admin’ accounts are held by TAP employees who have completed data protection training. All users can delete their own accounts.
Internal systems are protected by 2-step authentication as a minimum, including employee email accounts.
We carry out penetration testing on all key systems, including data stores, at least once annually. Testers simulate an attack under controlled conditions, with the aims of:
- breaching the confidentiality of data stored by, or on behalf of, The Ambassador Platform
- identifying the level of exposure to a targeted or untargeted attack
- identifying whether an attack could penetrate the VPC
- disabling internal infrastructure
- reducing or otherwise affecting the availability of the service
We monitor continuously using both AWS services and external services such as New Relic. We have processes for backups, updates, patches and disaster recovery.
All vulnerabilities are categorised using a traffic-light system and patches are released within 48 hours; in most cases within two hours. Errors and events are logged for 90 days. Backups are automated by AWS and checked daily for integrity. We perform vulnerability assessments on an ongoing basis with a monthly review.We have an RPO of under 6 hours and RTO under 2 hours.
Developers and account managers undergo a data protection training course provided by High Speed Training. We also take basic security measures including a 'monitor-off' policy, antivirus policies, and password management.