This article covers the technical and organizational controls RecMan uses to protect customer data day to day.
Encryption
- In transit: All data transmitted between users and RecMan is encrypted using minimum TLS 1.2 or 1.3 protocol.
- At rest: Stored data is encrypted using AES-256 or equivalent.
Authentication and access control
Application access security:
- Authentication options: Supports username/password, Multi-Factor Authentication (MFA via SMS, Vipps, BankID, hardware keys like Yubikey), and Single Sign-On (SSO) via SAML 2.0 / OIDC (including Microsoft Entra ID and Google Workspace).
- Customer responsibility: Customer account administrators retain full control over their tenant's user management, including enforcing mandatory MFA policies, assigning user roles, and revoking internal access.
Internal RecMan access control principles:
- Least-privilege principles: RecMan staff access to production systems and data strictly enforces least-privilege and need-to-know access, governed by Role-Based Access Control (RBAC).
- Periodic access reviews: RecMan conducts formal access reviews on a regular basis across all infrastructure, internal tools, and third-party SaaS platforms. Any excessive or outdated permissions are revoked immediately.
- Infrastructure security: Engineer access to RecMan’s cloud infrastructure requires a secure, encrypted VPN combined with mandatory Multi-Factor Authentication (MFA).
- Authentication standards: Internal accounts enforce strong password complexity policies combined with mandatory Multi-Factor Authentication (MFA) across all core platforms, identity providers, internal infrastructure, and third-party SaaS applications.
- Prompt offboarding: Personnel lifecycle processes ensure employee access across all systems, VPNs, and internal tools is revoked immediately upon termination or role change.
Threat detection and monitoring
Corporate security controls:
- RecMan utilizes a centralized Security Information and Event Management (SIEM) system to continuously aggregate and analyze activity logs across all cloud infrastructure in real time. Audit logs are stored in a read-only, tamper-proof environment to prevent unauthorized modification.
- Security monitoring is backed by an external, 24/7 managed Security Operations Center (SOC) that monitors real-time alerts, analyzes potential threats, and coordinates emergency response.
- Corporate devices are managed through an MDM (Mobile Device Management) solution that enforces security configurations and enables remote wiping if needed, with EDR (Endpoint Detection and Response) protecting devices from malware and other threats in real time.
- RecMan maintains a documented Incident Response Plan (IRP) with defined notification procedures for affected customers. The plan is reviewed and tested annually through simulated incident drills.
File security (product feature):
- All files uploaded to the solution can be automatically scanned for malware in real time via the Antivirus feature, a paid add-on customers can activate. A detected malicious file is quarantined immediately, and a predefined incident response procedure is triggered. Independent of this, RecMan may periodically run a manual scan across some or all files in the solution, as an additional check on our overall security exposure.
Vulnerability and patch management
RecMan maintains a continuous vulnerability management program combining automated monitoring, regular external audits, and proactive patching.
- Penetration testing: Penetration testing and application security testing are performed on a regular basis, according to the schedule, with every major release tested before deployment.
- Vulnerability disclosure: We operate a coordinated vulnerability disclosure program (Bug Bounty Program) providing independent researchers a secure channel to responsibly report security findings.
- Automated code and dependency scanning: All code updates undergo mandatory peer review, Static Application Security Testing (SAST), and automated Software Composition Analysis (SCA) to detect known vulnerabilities in third-party libraries prior to production deployment.
- Continuous cloud and infrastructure assessments: Cloud infrastructure and workspace configurations are continuously assessed against industry standards (AWS Security Best Practices and CIS Benchmarks), supported by formal annual compliance reviews.
- Remediation SLAs: Identified vulnerabilities are categorized by risk impact (CVSS rating) and remediated within strict internal service-level targets.
- Patch verification: All security patches undergo mandatory post-deployment verification in production to confirm issue resolution before formal ticket closure.
Secure development lifecycle
- Development, staging/testing, and production environments are strictly segregated and isolated at the infrastructure level.
- Every code change advances through a multi-stage automated deployment pipeline. Code must pass automated test suites, mandatory peer code review, and staging verification before being authorized for production.
- Code changes undergo automated Static Application Security Testing (SAST) and third-party dependency scanning within the pipeline to identify vulnerabilities prior to deployment.
- Production deployments go through an automated pipeline with mandatory review and a separate deployment-approval step, so no one can push code directly to production unreviewed.
- Development and testing environments use synthetic or anonymized data. Production customer data is strictly prohibited in non-production environments, except under explicit written agreement for dedicated troubleshooting.
Network and Infrastructure security
- Cloud networks are monitored continuously using Amazon GuardDuty for real-time threat detection and anomaly analysis across VPC flow logs.
- Full encryption is enforced for all data in transit across internal cloud networks and public endpoints using minimum TLS 1.2/1.3.
- Network access is governed by restrictive Security Groups and Network Access Control Lists (NACLs) operating on least-privilege principles. Direct administrative access is restricted to authorized IPs via encrypted VPN connections.
- Ingress traffic is managed via Load Balancing (ELB), Amazon CloudFront (CDN), and Web Application Firewalls (WAF) to provide automatic traffic distribution, DDoS mitigation, and application protection.
Security awareness
- Every employee receives mandatory security awareness training upon hire and regularly throughout the year, covering phishing awareness, data privacy, social engineering, and the safe, compliant use of AI tools.
- Software engineers and technical teams complete specialized periodic training in secure coding practices aligned with the OWASP Top 10 standards.