We know how critical data security is these days. Zymplify’s platform is hosted by a UK based data-centre. The Zymplify application is protected by a firewall and data exchanged between yourselves and the application is encrypted in transit. We utilise the services of an independent third-party professional certification company to perform penetration testing, to validate our data security policies and practices. See below for more details.
Does Zymplify encrypt data in transit?
The connection to this site is encrypted and authenticated using a strong protocol (TLS 1.0, 1.1, 1.2), a strong key exchange (ECDHE_RSA with P-256), a strong cipher (AES_128_GCM) and 2,048-bit keys.
Is Zymplify protected by a firewall?
Yes. Config Server Firewall (or CSF) is an advanced firewall for Linux distributions and Linux based VPS. In addition to the basic functionality of a firewall – filtering packets – CSF includes other security features, such as login/intrusion/flood detections etc.
Building
Room
Climate
Power
Security
Cabling and Connectivity
Fire Suppression
Penetration Testing & Vulnerability Testing
Zymplify bring in industry respected 3rd party penetration testing firms once a year to carry out full penetration testing on our products. The latest penetration test was carried out in June 2017 by Info-Assure who are certified CREST security testers. We have stringent internal audit procedures to ensure compliance with the data protection act. Our development team carry out vulnerability testing on an ongoing basis to identify and quickly respond to flaws.
Backups
We take full back-ups of the database 4 times per day to ensure that up to date and accurate data is available for restore in the case of disaster recovery. In addition our data centre has full disaster recovery procedures in place in line with ISO 9001 and take regular back-ups of the data on a daily basis.
Zymplify are committed to ensuring that all data processing is carried out in line with the General Data Protection Regulation (GDPR).
We are committed to Data Protection by Design and Default and we continue to develop features which will assist companies in ensuring that their marketing campaigns comply with the GDPR.
The steps we have taken include but are not limited to:
Our Data Protection Officer (Michael Green) has completed the EU GDPR Practitioner Certification (ISO 17024-accredited) and is on hand to answer any GDPR related queries, please get in touch via dpo@zymplify.com