Security Policy

Last updated: July 2021

 

Because Pave is a hosted Software-as-a-service product, we recognise that security is crucial. This page outlines our security and backup policies.

 

PAVE DOES NOT STORE CREDIT CARD INFORMATION

Our system integrates with Stripe, which is a PCI compliant payment processor. When entering credit card information, a request is made directly to Stripe using SSL.

 

ACCESS TO ALL PAVE’S SERVERS IS SECURE
  • Firewalls on all servers are set to default-deny.
  • Database connections are only accepted from other Pave servers on the internal private subnet.
  • All communication with servers (outside of public HTTP/HTTPS access) is over encrypted secure shell (SSH) and password authentication is disabled. SSH authentication is available only via public/private key authentication.
  • All of Pave’s servers are hosted on Amazon Web Services (AWS)
PAVE SERVERS AND SOFTWARE ARE RUNNING THE LATEST VERSIONS OF SOFTWARE AND SECURITY PATCHES
  • We strive to keep all server software on the latest version; however, when that is not possible, we do ensure that the latest security patches are installed and up-to-date
PAVE IS WRITTEN TO PROTECT AGAINST SQL INJECTION ATTACKS

Pave is built on the NodeJS platform and uses all the built-in protections for sanitising query parameters in SQL statements.

DATA IS STORED SECURELY

Data is hosted on Amazon EC2 and Amazon RDS with encryption enabled.

AVAILABILITY

Pave runs two hot-hot server instances side by side with AWS meaning in the highly unlikely scenario there is a server outage, the back-up server is automatically enabled and there is no noticeable loss of service to any user of our applications. Each of AWS' server instances operate at a best-in-class “5 nines” or 99.999% uptime and availability. More can be read here;

https://aws.amazon.com/blogs/publicsector/achieving-five-nines-cloud-justice-public-safety/

 

ACCESS TO PAVE IS SECURE

All access to Pave is over a secure (SSL encrypted) connection.

 

ACCESS IS LOGGED

All activity on a company is logged and is available in the “Audit Log” maintained for each company in the system.

 

EMPLOYEE SECURITY

All employees are required to sign a confidentiality agreement. Each employee is given a separate login to the system and all page requests are logged and backed up. Access to any identifiable information related to projects, contacts and deals is only available on the principle of least privilege and not available outside of the engineering team under any circumstances.

 

BACKUP POLICY

Backups are stored offsite and are encrypted. Pave performs daily, weekly, and monthly backups of the entire system. These backups are made to Amazon S3 which stores data in multiple facilities and on multiple devices within each facility. Amazon S3 performs regular, systematic data integrity checks.

 

 

PII AND COOKIES

Information about what we collect is outlined in our privacy policy at: https://www.yourpave.com/privacy-policy/

Cookies are required for normal operation of Pave however, no PII is stored in any of the cookies that Pave uses.

 

For more information, you can reach our Privacy Officer / Data Protector Officer on privacy@yourpave.com.