Applivery is a European UEM platform that helps organizations manage, secure, and automate devices. Our Trust Center shares our security, data protection, and compliance practices.
Control
Status
Remote access encrypted enforced
The company’s production systems can only be remotely accessed by authorized employees via an approved encrypted connection.
Production data segmented
The company prohibits confidential or sensitive customer data, by policy, from being used or stored in non-production systems/environments.
Network segmentation implemented
The company’s network is segmented to prevent unauthorized access to customer data.
Unique network system authentication enforced
The company requires authentication to the “production network” to use unique usernames and passwords or authorized Secure Socket Shell (SSH) keys.
Unique account authentication enforced
The company requires authentication to systems and applications to use unique username and password or authorized Secure Socket Shell (SSH) keys.
Production multi-availability zones established
The company has a multi-location strategy for production environments employed to permit the resumption of operations at other company data centers in the event of loss of a facility.
Control
Status
Security awareness training implemented
The company requires employees to complete security awareness training within thirty days of hire and at least annually thereafter.
Non-disclosure Agreement acknowledged by contractors
The company requires contractors to sign a non-disclosure agreement at the time of engagement.
Non-disclosure Agreement acknowledged by employees
The company requires employees to sign a non-disclosure agreement during onboarding.
Production inventory maintained
The company maintains a formal inventory of production system assets.
Asset disposal procedures utilized
The company has electronic media containing confidential information purged or destroyed in accordance with best practices, and certificates of destruction are issued for each device destroyed.
Production multi-availability zones established
The company has a multi-location strategy for production environments employed to permit the resumption of operations at other company data centers in the event of loss of a facility.
Remote access MFA enforced
The company’s production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.
Control
Status
Continuity and Disaster Recovery plans tested
The company requires employees to complete security awareness training within thirty days of hire and at least annually thereafter.
Incident response plan tested
The company tests their incident response plan at least annually.
Access requests required
The company ensures that user access to in-scope system components is based on job role and function or requires a documented access request form and manager approval prior to access being provisioned.
Backup processes established
The company’s data backup policy documents requirements for backup and recovery of customer data.
Incident response policies established
The company has security and privacy incident response policies and procedures that are documented and communicated to authorized users.
Configuration management system established
The company has a configuration management procedure in place to ensure that system configurations are deployed consistently throughout the environment.
Management roles and responsibilities defined
The company management has established defined roles and responsibilities to oversee the design and implementation of information security controls.
Service description communicated
The company provides a description of its products and services to internal and external users.
Security policies established and reviewed
The company’s information security policies and procedures are documented and reviewed at least annually.
Support system available
The company has an external-facing support system in place that allows users to report system information on failures, incidents, concerns, and other complaints to appropriate personnel.
Roles and responsibilities specified
Roles and responsibilities for the design, development, implementation, operation, maintenance, and monitoring of information security controls are formally assigned in job descriptions and/or the Roles and Responsibilities policy.
Physical access processes established
The company has processes in place for granting, changing, and terminating physical access to company data centers based on an authorization from control owners.
Third-party agreements established
The company has written agreements in place with vendors and related third-parties. These agreements include confidentiality and privacy commitments applicable to that entity.
Incident management procedures followed
The company’s security and privacy incidents are logged, tracked, resolved, and communicated to affected or relevant parties by management according to the company’s security incident response policy and procedures.
Remote access MFA enforced
The company’s production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.
Control
Status
Vulnerability and system monitoring procedures established
The company's formal policies outline the requirements for the following functions related to IT / Engineering:
Control
Status
Privacy policy established
The company has a privacy policy is in place that documents and clearly communicates to individuals the extent of personal information collected, the company’s obligations, the individual’s rights to access, update, or erase their personal information, and an up-to-date point of contact where individuals can direct their questions, requests or concerns.
Data retention procedures established
The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data.
Data deletion requests handled
The company validates deletion requests and once confirmed are flagged and the requested information is deleted, in accordance with applicable laws and regulations.
Continuity and Disaster Recovery plans established
The company has Business Continuity and Disaster Recovery Plans in place that outline communication plans in order to maintain information security continuity in the event of the unavailability of key personnel.
Asset disposal procedures utilized
The company has electronic media containing confidential information purged or destroyed in accordance with best practices, and certificates of destruction are issued for each device destroyed.
Production multi-availability zones established
The company has a multi-location strategy for production environments employed to permit the resumption of operations at other company data centers in the event of loss of a facility.
Remote access MFA enforced
The company’s production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.