SOC 2 Type II
We built our controls around the SOC 2 trust services criteria: physical security, data storage, access control and change management. An independent auditor tests those controls over a full period every year, so our customers can be confident they are in a secure, reliable and properly controlled environment.
SOC 2 is the AICPA framework for service organizations that host or process customer data. A Type II report does not just describe the controls; it shows how they operated over the audit period. Contact us for the current report under NDA.
Contact us at sales@esecuredata.com for our SOC 2 report.
ISO 27002
As a company we have developed standard organizational security standards and effective security management practices. Our customers can be reassured that their business and governance requirements are met.
Our security management guidelines include:
- Security policy
- Organization of information security
- Asset management
- Physical and environmental security
- Communications and operations management
- Access controls
- Information systems acquisition, development, and maintenance
- Information security incident management
- Business continuity management
- Compliance
PIPEDA
We are fully compliant with all mandatory PIPEDA provisions. These include, but are not limited to:
- Consent is garnered for collection of personal information
- Collection of personal information is limited to reasonable purposes
- Limited use and disclosure of personal information
- Limited access to personal information
- Stored personal information must be accurate and complete
- Designated role of the Privacy Officer
- Policies and procedures for breaches of privacy
- Measures for resolution of complaints
- Special rules for employment relationships
PHIPA
PHIPA is often considered the Canadian equivalent to HIPAA (Health Insurance Portability and Accountability Act). Note that under PHIPA, consent for stored information is given to the healthcare provider that obtains and maintains the data, not to the hosting provider.
As an IT service provider, we ensure the following:
- To send a notification of any privacy breach to the customer as soon as possible
- To provide a plain language description of our services
- To have our own written privacy policies
- To prepare an audit trail feature to track the use of our database
- To have written risk assessment of our systems
eSecureData is 100% owned and operated in Canada.
For additional information, visit www.ipc.on.ca (opens in a new tab).
Contact us at sales@esecuredata.com for more information on PHIPA.
COBIT5
COBIT5 is an industry-leading IT framework for the governance and management of enterprise IT, and a critical component of our compliance program. Clients can work directly with certified staff to build and meet their specific IT requirements.
The COBIT5 framework focuses on several distinct areas that help meet compliance and governance criteria, including:
- Audit and assurance for managing vulnerabilities and ensuring compliance
- Risk management for evaluating and optimizing enterprise risk
- Information security to oversee and manage information security
- Governance of enterprise IT that ensures alignment of IT goals and strategic business objectives