GDPR
TAC Security CASA Tier 2
Microsoft publisher attestation
✔ Single Authentication Enforced
PREDIMAIL requires secure authentication to access databases and production systems using unique SSH keys or secure credentials.
✔ Restricted Access to Sensitive Data
Only authorized users with a business need can access production databases and infrastructure.
✔ Secure Remote Access
Remote access to production systems is restricted to authorized employees using Multi-Factor Authentication (MFA) and encrypted connections.
✔ Network Monitoring and Protection
PREDIMAIL implements an intrusion detection system and regularly reviews firewall rules to prevent unauthorized access.
✔ Log Management and Monitoring
A log management system and infrastructure monitoring tools ensure proactive threat detection and system stability.
✔ Network Segmentation and Isolation
The network is segmented to prevent unauthorized access to customer data and reduce security risks.
✔ Data Encryption
All stored and transmitted data is encrypted to ensure confidentiality and integrity.
✔ Access Management and User Controls
Access is strictly controlled and revoked immediately upon employee departure.
✔ Compliance and System Audits
Regular self-assessments are conducted to ensure compliance with security standards.
✔ Security Awareness and Training
All employees undergo security awareness training upon onboarding and at regular intervals.
✔ Confidentiality and Contractual Commitments
Employees and contractors must comply with strict confidentiality agreements and a code of conduct.
✔ Device and Data Management
Removable media are encrypted, and a Mobile Device Management (MDM) system ensures secure handling of endpoints accessing sensitive data.
Product Security
✔ Secure Transmission Protocols
All communications and data transfers use encrypted protocols to ensure security.
✔ Proactive Vulnerability Management
Regular vulnerability scans are performed, and all critical flaws are immediately remediated.
✔ Business Continuity and Disaster Recovery
Business continuity and disaster recovery plans are in place and regularly tested to ensure service resilience.
✔ Cybersecurity Insurance
PREDIMAIL maintains cybersecurity insurance to mitigate the financial impact of potential service disruptions.
PREDIMAIL Labs is SOC 2 Type II and GDPR compliant, with regular external audits and penetration testing to ensure data security.
SOC 2 Type II Audit: An external review that verifies our security practices over time, confirming our commitment to keeping your data safe.
GDPR Compliant: We follow the EU’s data protection standards, ensuring your personal data is managed securely and responsibly.
Penetration Testing: Regular tests to identify and fix potential system vulnerabilities, keeping your data protected.
These measures help us maintain high standards of security and privacy for our users.