GovSpend
Prismatic iPaaS Data Privacy and Security Information
Pages
7
Time to read
10 mins
Publication
Language
English
Pages
7
Time to read
10 mins
Publication
Language
English
This guide outlines the data privacy and security practices of Prismatic, specifically designed as a lite version of their standard security questionnaire for prospective clients. It details compliance with industry regulations such as SOC 2, HIPAA, GDPR, and CJIS, and mentions ongoing efforts towards FedRamp compliance. The document describes the data governance policies, including data classification and retention practices, as well as physical security measures implemented at data centers. It also covers employee training on privacy and security best practices, access control management, and the encryption methods used to protect data in transit and at rest. Furthermore, it explains the incident response protocol for security incidents, compliance with global data protection laws, and the continuous monitoring of infrastructure for security threats. The guide concludes with information on risk management regarding third-party vendors and the processes in place for secure development and deployment of new features.