Data security and privacy are the top priorities in OnePageCRM and are ingrained in every aspect of our business. Since security standards are constantly evolving, our team never stops refining the system and processes to make sure that our customers get world-class data security and encryption. To provide additional insights into our Security Program we have prepared this overview.
The OnePageCRM development team consists of trusted and experienced developers that continuously evaluate our coding practices to recognize and timely address vulnerabilities.
We maintain best practices to ensure your account remains secure:
OnePageCRM has a dedicated Security Team. Their job consists of:
OnePageCRM undergoes an annual security assessment by a world-renowned security audit company which consists of comprehensive penetration testing including:
OnePageCRM also has an active Vulnerability Disclosure Program.
OnePageCRM believes in shared responsibility when it comes to protecting your data.
OnePageCRM is responsible for the security of your account but you are responsible for security within your account.
When a user visits any OnePageCRM application or API, all traffic is encrypted in transit via HTTPS with a minimum supported TLS version of 1.2 and with a modern set of cipher suites recommended by Mozilla. We are graded A+ in the Qualys SSL Server Test.
When user data hits OnePageCRM systems, it is stored encrypted at rest. This is done using the industry-standard AES-256 algorithm.
In addition to the disk-level encryption described above, very sensitive fields are also encrypted within the database. Passwords are salted and hashed with SHA256. Other sensitive fields like API keys and OAuth2 tokens are encrypted within the database using encryption keys stored on AWS Secrets Manager.
OnePageCRM team is trained according to the company’s Strong Password Policy:
OnePageCRM uses a top-tier, third-party data hosting provider Amazon Web Services (AWS). AWS provides 24/7/365 monitoring and surveillance, on-site security staff, and regular ongoing security audits. You can view more information on AWS data controls and AWS data security and privacy resources. AWS also provides a SOC 2 report for their cloud computing service.
OnePageCRM uses AWS servers located in North Virginia, U.S., and Dublin, Ireland to store your data. In addition, users have the option to select in which AWS region they would like their attachments to be stored.
Currently, for our European and other non-U.S. customers, this means that your personal information is transferred to AWS’s servers in the U.S. OnePageCRM relies on Standard Contractual Clauses (SCCs) included in the AWS GDPR Data Processing Addendum. SCCs are validated by the Court of Justice of the European Union as a legal mechanism for transferring data outside the European Economic Area (EEA).
To fulfill a range of our business functions we use third-party suppliers to whom we transfer some of your personal information. OnePageCRM uses the Standard Contractual Clauses with all of our sub-processors based outside the EEA. The list of our sub-processors can be found in our Privacy Policy. OnePageCRM ensures that the third-party suppliers have an adequate level of protection of personal data in their operations. To learn more about international transfers, visit our GDPR page.
OnePageCRM believes in security at every layer of the stack. This includes the networking and server layer. The following highlights some of the security measures taken:
We back up your data on a nightly basis. All backups are replicated to another AWS region for redundancy and fault tolerance purposes. These backups are stored in a readily recoverable state for a two-week period before being put in cold storage for another 90 days at which point they are fully deleted.
OnePageCRM does not have the ability to delete your account. You may delete your own account by following the instructions here.
Once your OnePageCRM account has been deleted, it can remain in backups for up to 114 days.
Please note that OnePageCRM is required by law to keep some limited information for a period of time to comply with a legal or regulatory obligation. For more information, please see the Privacy Policy.
The OnePageCRM dedicated security team continuously monitors security systems, event logs, notifications, and alerts from all systems to identify and manage threats.
OnePageCRM has an incident response procedure in place. Incident response training is conducted on a regular basis. The incident response plan is reviewed annually.
All incidents, however minor, including training incidents, are treated with the utmost attention. Suspected incidents are investigated and dealt with by the core security team who follows our Incident Response Plan. All incidents are reviewed and lessons learned are built back into our Response Plans.
OnePageCRM security team maintains a Disaster Recovery Plan. According to this plan, the recovery time and recovery point depend on the reason for the failure. The plan also outlines the worst case, such as a full database restore from the last daily backup and application redeployment to a new AWS region. In this situation, the recovery point objective (RPO) is to the last daily backup and the recovery time objective (RTO) is 6 hours. We maintain over 99.9% uptime for our services. Our application status page can be viewed here.
In the event of a breach of security, we will inform you without undue delay and use our best efforts to take all possible measures to neutralize the intrusion and minimize the impact.
We comply with GDPR requirements to report any incidents to our controllers and any affected parties within 72 hours.
More specific information about Security in OnePageCRM can be found in our Knowledgebase.
If you have any security-related questions or concerns, please get in touch at support@onepagecrm.com.