✨ Vaultedge will be at MBA Annual 24. Meet Us
Logo of Vaultedge

Vaultedge

Think Labs Inc DBA, Vaultedge Software, registered at 8951 Cypress Waters Boulevard Suite 160 Coppell, TX 75019 United States and Vaultedge Software Pvt Ltd registered at No.467/468, BHIVE Workspace, Shri Krishna Temple Rd,  Bengaluru Urban, KA, 560038 , recognises that the confidentiality, integrity, and availability of information and data created, maintained, and hosted by us are crucial to the success of our business and the privacy of our partners.

As a trusted provider, Vaultedge is committed to offering transparency regarding our security practices, tools, resources, and responsibilities. We aim to ensure that our customers can trust us as their secure and compliant partner in automating their document processing workflows.

Our security posture outlines the comprehensive measures we take to identify and mitigate risks, implement industry best practices, and consistently improve our security processes to safeguard the data and operations of our customers.

Compliance

Our security measures meets industry standards for data protection and security.

SOC 2
Complaint

Frequently asked questions

Is encryption at rest used for all data?

Yes, Vaultedge encrypts all data at rest using industry-standard AES-256 encryption to safeguard sensitive information from unauthorized access.

Is all access granted in accordance with the principle of least privilege?

Yes, Vaultedge strictly follows the principle of least privilege, ensuring that users have only the minimum level of access required to perform their roles effectively. Access permissions are periodically reviewed and adjusted accordingly.

Is multi-factor authentication (MFA) required to access information assets remotely?

Yes, Vaultedge requires multi-factor authentication (MFA) for all remote access to our information assets, providing an additional layer of security to prevent unauthorized access.

Is there a formal change management policy actively in use?

Yes, Vaultedge has a formal change management policy in place to govern all changes to our systems. This policy ensures that all changes are thoroughly reviewed, tested, and approved before implementation.

Is all privileged account access reviewed at least quarterly?

Yes, Vaultedge conducts quarterly reviews of privileged account access to ensure that only authorized personnel have access to critical systems and sensitive data.

Is there an incident response plan that is regularly maintained?

Yes, Vaultedge has a comprehensive incident response plan that is regularly updated and tested to ensure swift and effective responses to any security incidents.

Is there a business continuity plan?

Yes, Vaultedge maintains a business continuity plan, which is tested annually to ensure that our services remain available during unexpected disruptions.

Is data loss prevention (DLP) technology in use?

Yes, Vaultedge employs data loss prevention (DLP) technology to monitor, detect, and prevent potential data breaches or unauthorized data transfers.

Are all user entitlements for all systems reviewed at least annually, with manager signoff required?

Yes, Vaultedge conducts an annual review of all user entitlements across our systems, with managerial signoff required to ensure access rights are appropriate and justified.

Is there a cloud security policy in place?

Yes, Vaultedge has a robust cloud security policy that governs the use of cloud services, ensuring that our cloud infrastructure remains secure and compliant with industry standards.

Are security logs retained for at least 90 days?

Yes, Vaultedge retains security logs for a minimum of 90 days, allowing for comprehensive analysis and auditing of security events.

Are penetration tests conducted by a third party or certified internal staff at least annually?

Yes, Vaultedge conducts annual penetration tests through certified third-party security firms to identify and address any vulnerabilities in our systems.

Is there a privacy management program in place with respect to regulatory requirements for protecting personal data while in transit, usage & storage?

Yes, Vaultedge has a comprehensive privacy management program in place to ensure the protection of personal data throughout its lifecycle—during transit, usage, and storage—in compliance with relevant regulatory requirements.

Does the information asset register identify which assets have privacy-related data?

Yes, Vaultedge’s information asset register identifies assets that contain privacy-related data, ensuring that proper security controls are implemented to protect such data.

Are all employees made aware of their responsibilities to protect personal information?

Yes, all Vaultedge employees are trained on their responsibilities to protect personal information during onboarding and through ongoing security awareness programs.

Are laws, regulations, and compliance requirements regularly reviewed and tracked to ensure the organization stays compliant?

Yes, Vaultedge regularly reviews and tracks applicable laws, regulations, and compliance requirements to ensure continuous compliance with security and privacy standards.

Is there a breach notification process, and are all employees aware of how to invoke the process?

Yes, Vaultedge has a formal breach notification process in place, and all employees are trained on how to recognize and report a data breach, ensuring timely notification to affected parties and regulatory authorities.

What’s Vaultedge’s Password Policy for users?

Vaultedge enforces a password policy that includes the following complexity standards:

• Minimum Length: Passwords must be at least 8 characters long.
• Character Requirements: Passwords must include a mix of the following:
• At least one uppercase letter (A-Z)
• At least one lowercase letter (a-z)
• At least one digit (0-9)
• At least one special character (e.g., !, @, #, $)
• No Reuse of Old Passwords: Users are not allowed to reuse their last three passwords.
• Account Lockout: Accounts get locked after multiple failed attempts to ensure security, and access tokens are refreshed every 30 days.

These measures are designed to maintain the integrity and confidentiality of data on our platform. We recommend that all users adhere to these guidelines to uphold a high level of security.