Advanced Role-Based Access and Audit Controls
Advanced Role-Based Access and Audit Controls
- Two-Factor Authentication: Adds an additional layer of security for user authentication.
- Granular Role-Based Controls: Implements team-based and channel-based access with features like phone masking.
- Internal Restrictions: Ensures data is not accessible outside the organization.
- Exhaustive Audit Logs: Keeps detailed records of all data interactions.
- Controlled Troubleshooting: Allows troubleshooting only with approved access.
Secure and Scalable Hosting Infrastructure
Secure and Scalable Hosting Infrastructure
- Scalability: Supports both horizontal and vertical scaling for consistent performance.
- Advanced Cloud Infrastructure: Implements cutting-edge cloud infrastructure and data security principles.
- Role-Based Authentication: Ensures data is accessible only to authorized personnel.
- Secure Data Downloads: Data extraction is controlled and requires necessary approvals.
- Integration Flexibility: Offers various secure integration models, including HTTPS.
- Containerization: Utilizes Docker for secure and efficient application deployment.
- Inbuilt Security in AWS and MongoDB Atlas: Leverages inherent security features for enhanced protection.
Enhanced Data Security Measures
Enhanced Data Security Measures
- HTTPS for Secure Communication: Utilizes trusted, auto-renewable certificates for HTTPS integrations.
- Encryption: Ensures all data is encrypted in transit (TLS 1.2/1.3) and at rest (AES-256)
- Authorized User Access: Restricts data viewing to authorized users on the Gallabox Web/App Console, additionally we enforce Multi-Factor Authentication (MFA) for all users
- Role-Based Data Access: Implements client-defined, authenticated roles for data access.
- Database Security: Limits database access to approved IPs within the VPC.
- Audit Trail: Maintains detailed logs of all data access and modifications.
Robust Backup and Recovery Infrastructure
Robust Backup and Recovery Infrastructure
- Geographic Distribution: Backups are distributed across multiple zones, with a primary data center in the US.
- Continuous Backup and Easy Restoration: Offers 2-hour continuous backup and efficient one-click data restoration.
Secure Source Code Management
Secure Source Code Management
- Private Repositories: Manages source code in secure, private GitHub repositories.
- Two-Factor Authentication: Requires this for all contributors’ GitHub accounts.
- Regular Key Rotation: Periodically rotates SSH keys and Personal Access Tokens.
- Strategic Release Management: Employs well-defined branching strategies for controlled releases and rollbacks.
- Continuous Integration: Uses Jenkins for continuous integration and code audits.
Data Security Controls
Gallabox operates a multi-layered set of security controls. All of the controls below were tested by an independent auditor as part of our SOC 2 Type II audit for the period January 16, 2025 to January 15, 2026, with no exceptions noted.Predict — proactive risk assessment and monitoring
- Penetration testing — a third party performs vulnerability assessments and penetration tests at least annually, and identified vulnerabilities are remediated and re-verified
- Independent audit — an annual SOC 2 Type II examination covering the Security, Availability, and Confidentiality criteria
- Risk assessments — formal risk assessments are performed annually, producing a risk register and a tracked treatment plan
- Internal audit — an internal assurance function reviews our governance, risk management, and control processes each year
Prevent — prevention of security incidents
- Access control — role-based access control with least privilege; access is approved in writing before credentials are issued and reviewed at defined intervals
- Multi-factor authentication — enforced for user accounts and for administrative access to our cloud consoles
- Data encryption — AES-256 at rest, TLS 1.2/1.3 in transit, governed by a documented cryptography standard that also covers key rotation
- Network security — production systems run inside a VPC protected by security group rules; database access is limited to approved IPs
- System hardening — production systems are hardened against CIS benchmarks
- Secure development — documented SDLC with peer code review, segregated environments, and security checks in CI/CD
- Personnel controls — background checks, signed NDAs and acceptable-use policies, and security awareness training on hire and annually thereafter
Detect — threat monitoring and logging
- Security monitoring — logging and monitoring systems watch in-scope systems for possible or actual security breaches and generate alerts
- Endpoint protection — antivirus and anti-malware on end-user devices with automatic definition updates; network traffic is inspected for malware, vulnerabilities, and insider threats
- Infrastructure monitoring — cloud workloads are monitored continuously for non-compliance with our configuration standards, with alerts on abnormal conditions
- Audit trail — detailed logs of data access and modification, available to you in the Activity Log
Correct — incident response and recovery
- Incident response plan — a documented plan assigns roles and response steps, and is communicated to both employees and customers
- Backups — incremental and full backups of production databases run daily, with continuous backup and one-click restoration
- High availability — the platform runs across multiple redundant availability zones with load balancing and auto-scaling
- Recovery testing — the business continuity and disaster recovery plan, including backup restoration, is tested at least annually
- Breach notification — we notify affected customers of a personal data breach without undue delay, as set out in our DPA
- Forensic investigation — root cause analysis after security incidents, followed by corrective action
In summary, Gallabox is fortified with a multi-faceted approach to data security, encompassing robust infrastructure, stringent access controls, comprehensive encryption, and proactive auditing and recovery measures. These practices collectively ensure the security and integrity of our client’s data, making our solution a reliable and trusted choice in the market.