Applivery Trust Center

Applivery is a European UEM platform that helps organizations manage, secure, and automate devices. Our Trust Center shares our security, data protection, and compliance practices.

Controls

Infrastructure Security

Control

Status

Remote access encrypted enforced

The company’s production systems can only be remotely accessed by authorized employees via an approved encrypted connection.

Production data segmented

The company prohibits confidential or sensitive customer data, by policy, from being used or stored in non-production systems/environments.

Network segmentation implemented

The company’s network is segmented to prevent unauthorized access to customer data.

Unique network system authentication enforced

The company requires authentication to the “production network” to use unique usernames and passwords or authorized Secure Socket Shell (SSH) keys.

Unique account authentication enforced

The company requires authentication to systems and applications to use unique username and password or authorized Secure Socket Shell (SSH) keys.

Production multi-availability zones established

The company has a multi-location strategy for production environments employed to permit the resumption of operations at other company data centers in the event of loss of a facility.

Organizational Security

Control

Status

Security awareness training implemented

The company requires employees to complete security awareness training within thirty days of hire and at least annually thereafter.

Non-disclosure Agreement acknowledged by contractors

The company requires contractors to sign a non-disclosure agreement at the time of engagement.

Non-disclosure Agreement acknowledged by employees

The company requires employees to sign a non-disclosure agreement during onboarding.

Production inventory maintained

The company maintains a formal inventory of production system assets.

Asset disposal procedures utilized

The company has electronic media containing confidential information purged or destroyed in accordance with best practices, and certificates of destruction are issued for each device destroyed.

Production multi-availability zones established

The company has a multi-location strategy for production environments employed to permit the resumption of operations at other company data centers in the event of loss of a facility.

Remote access MFA enforced

The company’s production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.

Internal Security Procedures

Control

Status

Continuity and Disaster Recovery plans tested

The company requires employees to complete security awareness training within thirty days of hire and at least annually thereafter.

Incident response plan tested

The company tests their incident response plan at least annually.

Access requests required

The company ensures that user access to in-scope system components is based on job role and function or requires a documented access request form and manager approval prior to access being provisioned.

Backup processes established

The company’s data backup policy documents requirements for backup and recovery of customer data.

Incident response policies established

The company has security and privacy incident response policies and procedures that are documented and communicated to authorized users.

Configuration management system established

The company has a configuration management procedure in place to ensure that system configurations are deployed consistently throughout the environment.

Management roles and responsibilities defined

The company management has established defined roles and responsibilities to oversee the design and implementation of information security controls.

Service description communicated

The company provides a description of its products and services to internal and external users.

Security policies established and reviewed

The company’s information security policies and procedures are documented and reviewed at least annually.

Support system available

The company has an external-facing support system in place that allows users to report system information on failures, incidents, concerns, and other complaints to appropriate personnel.

Roles and responsibilities specified

Roles and responsibilities for the design, development, implementation, operation, maintenance, and monitoring of information security controls are formally assigned in job descriptions and/or the Roles and Responsibilities policy.

Physical access processes established

The company has processes in place for granting, changing, and terminating physical access to company data centers based on an authorization from control owners.

Third-party agreements established

The company has written agreements in place with vendors and related third-parties. These agreements include confidentiality and privacy commitments applicable to that entity.

Incident management procedures followed

The company’s security and privacy incidents are logged, tracked, resolved, and communicated to affected or relevant parties by management according to the company’s security incident response policy and procedures.

Remote access MFA enforced

The company’s production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.

Product Security

Control

Status

Vulnerability and system monitoring procedures established

The company's formal policies outline the requirements for the following functions related to IT / Engineering:

  • Vulnerability management.
  • System monitoring.

Data and Privacy

Control

Status

Privacy policy established

The company has a privacy policy is in place that documents and clearly communicates to individuals the extent of personal information collected, the company’s obligations, the individual’s rights to access, update, or erase their personal information, and an up-to-date point of contact where individuals can direct their questions, requests or concerns.

Data retention procedures established

The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data.

Data deletion requests handled

The company validates deletion requests and once confirmed are flagged and the requested information is deleted, in accordance with applicable laws and regulations.

Continuity and Disaster Recovery plans established

The company has Business Continuity and Disaster Recovery Plans in place that outline communication plans in order to maintain information security continuity in the event of the unavailability of key personnel.

Asset disposal procedures utilized

The company has electronic media containing confidential information purged or destroyed in accordance with best practices, and certificates of destruction are issued for each device destroyed.

Production multi-availability zones established

The company has a multi-location strategy for production environments employed to permit the resumption of operations at other company data centers in the event of loss of a facility.

Remote access MFA enforced

The company’s production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.