Citrine Informatics
Citrine Informatics Security Program Overview
Pages
8
Time to read
8 mins
Publication
Language
English
Pages
8
Time to read
8 mins
Publication
Language
English
This document is a technical report detailing the security program of Citrine Informatics. It outlines the company's commitment to security, including its ISO 27001:2013 certification obtained in 2018 and renewed annually. The report describes the separation of authentication from authorization, ensuring that customer data and applications are completely segregated and encrypted. It highlights the operational security principles, including strict access controls and the unique encryption methods used for customer data. The document also discusses the continuous improvement processes in place, such as vulnerability management and incident response programs. Additionally, it covers physical security measures and the company's reliance on AWS for data center security. The report emphasizes the importance of compliance with legal and regulatory requirements, including GDPR, and the ongoing efforts to maintain a secure environment for customers' data and applications.