ComplyDog Security

Protecting and securing data at ComplyDog is our top priority.

Infrastructure

Infrastructure

System architecture

ComplyDog’s architecture is designed to be secure and reliable.

We require the use of a firewall and whitelisted IP addresses, and the use of network load balancers in order to optimize the bandwidth available per each server. We regularly monitor incoming and outgoing data using Network and Graph analytics provided by third-party tools, such as Google Cloud Platform, Digital Ocean, and DataDog. We utilize networking tools such as Cloudflare for firewall and whitelisting utilities that prevent, minimize, and alert of network attacks.

Services are accessible only by other services that require access. Access keys are rotated regularly and stored separately from our code and data.

Data centers

Our application is hosted and managed within Digital Ocean (DO) secure data centers. These data centers have been accredited under:

  • ISO 27001
  • SOC 1 and SOC 2
  • PCI-DSS

We make extensive use of the capabilities and services provided by DO to increase privacy and control network access throughout our system. You may view Digital Ocean Trust Certificates here.

Vulnerability scans

ComplyDog uses security tools to continuously scan for vulnerabilities. Additionally, vulnerabilities in third-party libraries and tools are monitored and software is patched or updated promptly when new issues are reported.

Firewall

Our servers are protected by firewalls and not directly exposed to the Internet.

Corporate network

ComplyDog runs a zero-trust corporate network. There are no corporate resources or additional privileges from being on ComplyDog’s corporate network.

Data

Data

Data storage

ComplyDog data stores are accessible only by servers that require access. Access keys are stored separately from our source code repository and only available to the systems that require them. Additionally, production environments are sandboxed from testing environments.

For more information, please see section PERSONAL INFORMATION WE COLLECT ABOUT USERS AND PARTICIPANTS on our Privacy Policy.

Our servers are located in Frankfurt, Germany, unless our customer agreements specify otherwise. We utilize cloud providers like Digital Ocean.

Backups

For disaster recovery and business continuity purposes, we maintain regular backups of customer data. ComplyDog-controlled backups may retain data for up to 90 days before being automatically overwritten or deleted in accordance with our backup lifecycle. Data deleted from active systems may therefore remain in backup copies for up to 90 days. These backups are not used for normal processing and are only accessed where necessary for recovery or security purposes. Certain subprocessors may operate their own backup and retention schedules in accordance with their applicable terms and data processing agreements.

Logs

We aggregate logs to secure encrypted storage. All sensitive information (including passwords, API keys, and security questions) is filtered from our server logs.

Processing

ComplyDog processes data only to fulfill its obligations as related to the Services outlined in our Terms of Service. All personal information for ComplyDog users and participants are shared to the minimal extent. Please see section HOW AND WHY WE USE YOUR PERSONAL INFORMATION in our Privacy Policy

Sharing with third parties

We only share data with the vendors listed in the subprocessors section on the ComplyDog GDPR Portal.

Breaches

Our internal GDPR and CCPA Compliance processes cover protocols for data breaches, user policies, and more.

Authentication

Authentication

Passwords

We never store passwords in a form that can be retrieved. Instead, we store an irreversible cryptographic hash using a function specifically designed for this purpose. Authentication sessions are invalidated when users change key information and sessions automatically expire after a period of inactivity.

Monitoring

We monitor and rate limit authentication attempts on all accounts.

User roles

We provide multiple user roles with different permissions levels within the product. Roles vary from account owners, to admins, users, and roles that limit visibility of Personally Identifiable Information (PII).

Encryption

Encryption

HTTPS

All ComplyDog web traffic is served over HTTPS. We force HTTPS for all web resources, including our REST API, web app and public website. We also use HSTS to ensure that browsers communicate with our services using HTTPS exclusively.

Encryption

Sensitive data is protected using appropriate technical and organisational measures. Data is encrypted in transit using HTTPS/TLS, and our hosting and infrastructure providers apply encryption and access controls to protect stored data. Access to production systems and sensitive information is restricted to authorised personnel and services on a need-to-know basis.

Policies

Policies

Policies

ComplyDog has developed a comprehensive set of security policies covering a range of topics. These policies are updated frequently and shared with employees.

Topics include, but are not limited to, general internal protocols, password and security/network policies for ComplyDog employees, including handling sensitive customer data.

Incident response

ComplyDog has a defined protocol for responding to security events.

Security training

All employees complete security training when they join and are continually refreshed.

Employee vetting

ComplyDog performs background checks on all new employees in accordance with local laws. The background check includes employment verification and criminal checks for US employees.

Confidentiality

All employees have signed confidentiality agreement with ComplyDog.

PCI compliance

All credit card payments paid to ComplyDog go through our payment processing partner, Stripe. Details about their security posture and PCI compliance can be found at Stripe’s Security page.

Disclosure

If you have any concerns or discover a security issue, please contact us directly. Our Security team will acknowledge receipt of each vulnerability report, conduct a thorough investigation, and then take appropriate action for resolution. We request that you do not publicly disclose any issue you discovered until after we have addressed it.

Other

Other

Business continuity process

Our internal Business Continuity Process (BCP) outlines protocols in the event of a disruption to normal operations.

Disaster recovery process

Our internal Disaster Recovery Process (DRP) outlines protocols to restore data in the event of disasters.

Security questionnaire request policy

Please note, ComplyDog only accomodates security questionnaire requests, modified DPA requests, or any other legal/vendor requirements for customers on our custom Teams plan. If you have bespoke legal and compliance needs, please get in touch with sales.
GDPRPowered by ComplyDog