Jemurai Logo

Last Updated: 11/6/2018

SecuritySignal.io Security Policy

SecuritySignal.io is built by Jemurai. Jemurai has the following open, published security policies that apply across the firm including the teams building and supporting SecuritySignal.io: https://github.com/jemurai/policy.

This policy set includes the following:

SecuritySignal.io Specific Security Policy

In addition to the above policies, SecuritySignal.io has some specific data security requirements that we can provide specific security policy direction for.

SecuritySignal.io Data Protection

The SecuritySignal.io system contains data that we consider the highest tier of criticality per our Data Classification Policy. Specifically, all of the following are considered SECRET and must be encrypted at rest and in transit.

  1. User’s passwords
  2. Client AWS credentials
  3. SecuritySignal.io client encryption keys

This explicitly means that:

SecuritySignal.io Access Controls

SecuritySignal.io Logging and Auditing