Objective: To educate the user on Duro's security methods and protocols.
Difficulty: Easy
In this article:
- Overview
- PCI Compliance
- Communications
- Data Storage
- Redundancy & Failover
- Security Policy
-
Security FAQs
- How often is user data backed up?
- How long is user data kept for?
- Do users have access to their backups? Can users store backups locally as a precaution?
- How do you guarantee data won’t be corrupted?
- What happens if a software update corrupts data? Do you have a system in place to roll back to the previous version?
- Do you have an SLA (Service Level Agreement)?
- What up time do you expect? What has been the up time in the past 6 months?
- What security measures do you offer to prevent unauthorized access to customers’ IP?
- Do you offer 2FA (2-Factor Authentication)?
- Do you offer SSO (Single Sign On)?
- What is your response time to an outage? Do you have an escalation process in place?
- How do I submit a vulnerability report?
- Where can I find the Drata monitoring page?
Overview
Here at Duro Labs we know that security is very important, so we’ve gone out of our way to ensure that all of our customers are well-protected. Here are some of the things that you might be interested to know:
PCI Compliance
Duro Labs complies fully with all federal laws and PCI (Payment Card Industry) requirements. All payment services are powered by Level 1 PCI Compliant partners, and all customer payment information is encrypted at all times. Additionally, no customer payment information is ever accessible to Duro Labs employees. This means that we have taken every action possible to prevent customer payment information from ever being compromised.
Communications
All interactions with Duro Labs software are processed through our online web platform at https://www.duro.app. This platform is secured and encrypted using 256 bit SSL certificates. This means that client interactions are safeguarded by the exact same technology that enterprise level banking systems use.
Data Storage
All client data is stored on Google's cloud-based platform. Google Cloud's services are considered “best in class” by Fortune 500 companies around the world. More information about Google Cloud security policies can be found at: https://cloud.google.com/security.
Redundancy & Failover
All user data is backed up multiple times per day so that we can recover your data In the unlikely event that an unforeseen problem comes up.
Security Policy
We also have an internal security policy that governs how our employees access our office network and manage internal data. This provides even more peace of mind for our customers. Duro’s security policy can be shared upon request.
Security FAQs
How often is user data backed up?
Duro’s database servers are configured to automatically create complete backups of all user data every six hours (four times per day).
How long is user data kept for?
Duro guarantees storage of all user data for the duration of their subscription and services contracts, plus an additional 3 months after cancelation of subscription and services.
Do users have access to their backups? Can users store backups locally as a precaution?
Yes. Duro can provide copies of backups of user data to authorized account administrators, in CSV formatted files. Requests for backup copies can be made in writing up until 3 months after the cancelation of subscription and services. Users can choose to store their data on any appropriate local storage device.
How do you guarantee data won’t be corrupted?
Duro runs a suite of automated regression tests prior to each code deployment to review and guarantee data integrity.
What happens if a software update corrupts data? Do you have a system in place to roll back to the previous version?
Yes. Duro can roll back to the most recent database backup, in the rare event of a corrupted data issue.
Do you have an SLA (Service Level Agreement)?
Duro’s application is hosted on Google Cloud and guarantees a 99.9% SLA. Further details of Google Cloud's SLA can be found at: https://cloud.google.com/terms/sla
What uptime do you expect? What has been the uptime in the past 6 months?
Duro has had 100% uptime over the past 6 months, except for scheduled maintenance and software updates. Regular updates to the Duro application are performed on a rolling deployment policy. This allows for 0% downtime while the application is being updated.
What security measures do you offer to prevent unauthorized access to customers’ IP?
Only select, authorized Duro employees have access to customer data.
Do you offer 2FA (2-Factor Authentication)?
Duro does currently implement 2FA. For more information, please see our article on Enable Two-Factor Authentication (2FA).
Do you offer SSO (Single Sign On)?
Yes. Users can choose to use Google OAuth to create accounts and log in to the Duro application using a Google Suite account. Companies can also integrate their SAML Identity provider to manage user accounts through their own SSO portal.
What is your response time to an outage? Do you have an escalation process in place?
Duro has 24/7 availability to respond to any critical issue. Duro administrators are located around the world, guaranteeing 24-hour availability. The expected response time to an outage report is under one hour.
How do I submit a vulnerability report?
To submit a vulnerability report to Duro Labs’s Product Security Team, please contact us at security@durolabs.co.
Where can I find the compliance monitoring page?
The compliance monitoring page can be found here.
Comments
0 comments
Please sign in to leave a comment.