How Is Security Handled In Cloudiway SaaS Platform?
We take your privacy and security seriously at Cloudiway, and we have invested significant effort into making our platform and your data secure.
Cloudiway provides a cloud-based application hosted on Windows Azure. It means that the software and data are centrally hosted and accessed by clients using a web browser and internet connection.
In addition, Cloudiway’s SaaS benefits from Windows Azure’s certifications, ensuring the security of Microsoft’s infrastructure, network, and physical security layers.
At Cloudiway, we take your privacy and security seriously and as such we have invested significant effort in making our platform and your data secure.
This document is intended to answer questions around the infrastructure and security associated with the software and the data.
Cloudiway uses the secure Windows Azure infrastructure to provide a secure and scalable platform to clients around the world.
Microsoft’s public auditor Deloitte has issued a Service Organization Control (SOC) 2 Type 2 report for Windows Azure in security, availability, and confidentiality trust principles.
100% of the infrastructure is hosted in Windows Azure.
Security and compliance
Cloudiway leverages Windows Azure certifications and attestations to provide assurance to Cloudiway and its customers to the security of the infrastructure, network, and physical security layers of Cloudiway’s cloud.
- Security: Physical and logical protection against unauthorized access.
- Availability: The system is operationally available for use as committed or agreed.
- Processing Integrity: System processing is complete, accurate, timely, and authorized.
- Confidentiality: All information is classified and protected as committed or agreed.
- Privacy: Personal information is collected, used, retained, and transferred as committed or agreed.
Audit trails and session logs record user activity and changes made to data by the user.
Cloudiway provides logs detailing when customers logged in and when changes to configuration were made.
Application layer security
All data transmitted between Cloudiway and the user is encrypted via HTTPS.
All data transmitted between the different cloud applications (Google Apps, Office 365, etc…) is encrypted via HTTPS.
The environment is backed up every day using Windows Azure backup facilities.
Restores are tested every month.
Your data is automatically destroyed after 90 days of inactivity. Backups of your data are also destroyed at that time.
If you want to delete your project manually, you will see a Delete option to the right of your project that you can click on. The database will become inaccessible for up to 10 days, and permanently deleted after that.
You can also contact our support team through the portal and ask to delete your data and accounts when you don’t need them anymore.
Cloudiway will never store your mail, file, or site data. Please read below for further details.
What data do we store
Nothing is stored internally. No data persists on the platform* and Cloudiway doesn’t ever store your mail, files, or site data (except Lotus Notes).
The migration takes place in real-time in memory. The migration engine connects to the source, pulls data, and pushes it in real-time.
*However, for the delta pass mechanism, a reference ID of each data migration is stored into internal caches (SQL databases) with the date of modification.
During a delta pass, this ensures that no data is duplicated, and for efficiency, only the changes are propagated.
Connections to the source and the target are done using HTTPS; the data is not transferred unencrypted over the internet.
For the GALSync product, all contact objects and their attributes are stored (cached) in the Cloudiway Azure environment. This allows the GALSync tool to check for and synchronize any changes made since the last sync.
Free/busy queries are performed in real-time.
Google and Office 365 free/busy queries are sent over HTTPS to the coexistence platform which in real-time queries the remote system.
Calendar data are not stored internally. No cache is implemented.
Access to the coexistence platform is authenticated and logged.
The mail routing service relays mail in real-time via a mail queue. If an email can’t be delivered, it can stay in this queue for up to an hour before a delivery report is sent and the email is removed from the queue. Mail routing data are not stored internally. No cache is implemented.
Credentials to connect to the different systems
Because the platform needs credentials to connect to the source and the target, you define connectors to connect to them and enter credentials that will be used for the connection.
These credentials are stored encrypted using AES 256.
We recommend that you create temporary passwords during your migration and change the password after the completion of your project.
Credentials to connect to the Cloudiway platform
Passwords are not stored in a reversible way.
A hash of the password is stored. During the connection, hashes are compared.
Cloudiway staff cannot know your password.