Security
Client data is the product. It is protected like one.
serviceMob holds a current SOC 2 Type II report. Client workloads run in serviceMob's managed AWS environment, with controls aligned to the SOC 2 Trust Services Criteria, on AWS infrastructure covered by AWS's own SOC 2 Type 2 report. Every tenant's data lives in its own database.
-
SOC 2 Type II
current report held by serviceMob; period and auditor available on request
-
One tenant, one database
network isolation and firewalls enforce the separation
-
TLS and at rest
encryption in transit and for every database
Attestation
What we attest to, and what AWS attests to.
serviceMob maintains an Information Security Program, communicated throughout the organization, that follows the criteria set out by the SOC 2 framework of the American Institute of Certified Public Accountants. The program is assessed by an independent third party, and serviceMob holds a current SOC 2 Type II report. The report period and the auditor are shared with prospective clients under NDA.
Where workloads run. Client workloads run in serviceMob's managed AWS environment, with controls aligned to the SOC 2 Trust Services Criteria, on AWS infrastructure covered by AWS's own SOC 2 Type 2 report. AWS's attestations cover the infrastructure layer; serviceMob's report covers the platform and the organization that runs it.
Controls
The controls, in the order an auditor asks about them.
Organizational security
- Information Security Program following the SOC 2 framework, reviewed and accepted by every team member
- Independent third-party assessments of security and compliance controls
- Independent third-party penetration testing at least annually
- Defined roles and responsibilities for the protection of customer data
- Security awareness training covering phishing, password management and current practice
- Confidentiality agreements before the first day; background checks in accordance with local law
Cloud and data security
- All services hosted on Amazon Web Services, in the United States
- Each tenant in its own database, with network isolation and firewalls enforcing the separation
- Development, staging and production on private networks, never publicly reachable
- One entry point: a load balancer in public subnets distributing traffic into a secured back end
- Encryption at rest for every database; TLS for every connection
- Vulnerability scanning, threat monitoring, and logging across cloud services
Access security
- Access to cloud infrastructure and sensitive tools limited to the employees whose role requires it
- Single sign-on and two-factor authentication where available, with strong password policies
- Least-privilege identity and access management
- Quarterly access reviews of everyone with access to sensitive systems
- A password manager on every company-issued laptop
Continuity, incidents and vendors
- Backups through the hosting provider's services, with monitoring that alerts the team to failures affecting users
- An incident response process with escalation, rapid mitigation and communication
- Annual risk assessments, including fraud considerations
- Vendor risk determined and reviewed before any new vendor is authorized
Questions
What security teams ask first.
Does serviceMob hold its own SOC 2 report, or rely on AWS's?
Both apply, at different layers. serviceMob holds a current SOC 2 Type II report for the platform and the organization. AWS's own SOC 2 Type 2 report covers the infrastructure the platform runs on. The report period and auditor are shared under NDA.
Where is our data, and who else can see it?
In AWS databases located in the United States, one database per tenant, with network isolation and firewalls between tenants. Data is encrypted at rest and in transit. Access inside serviceMob is limited to the roles that need it and reviewed quarterly.
How do we report a security concern?
Write to security@servicemob.com. Questions, comments and potential issues all go to the same address and follow the incident response process.
Bring your security questionnaire.
A working session can include your security lead. We answer the questionnaire against the controls above and share the report under NDA.