IT Portal - SOC 2 Type 2 and V4 Security

Sep 3, 2021

Security First

Security remains a top priority for the IT Portal platform. We are actively strengthening our security posture through multiple initiatives and certifications.

Current Security Measures

The platform implements comprehensive protection mechanisms:

  • Encryption Standards: Utilizes AES 256-bit encryption protocols for data protection
  • Personal Encryption Keys: Users receive individual encryption keys that protect usernames, passwords, and uploaded files—preventing even internal staff from accessing this data
  • Authentication Options: Supports built-in two-factor authentication alongside AD and SAML methods (Office 365/Duo integration)
  • Infrastructure Security: Cloud servers operate behind Cloudflare CDN rather than being directly exposed to the internet
  • Data Protection: Encryption applies both in transit and at rest

My Portal Features

Users can leverage the personal portal dashboard to:

  • Manage passwords with private encryption keys
  • Access a browser plugin for password management
  • Store personal documents securely

Certification Efforts

We have engaged Drata and accounting professionals to pursue SOC 2 Type 2 certification. Stakeholders may request completion reports by contacting our support team.

Recommendation

To maximize security, administrators should enforce Portal Version 4 by navigating to Admin Settings > Site Settings > Site Options.