ChatMetrics.com Security and Data Storage

Security and Data Storage

Data transmission and storage security is imperative in the modern enterprise. That’s why we have taken all measures to keep all information and data appropriately protected.

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

However, the transmission of information via the internet is never completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

Our data centers, provided by AWS, are located in Sydney, Australia. They are one the world’s most security environment as AWS is the market leader in hosting and data safety.

Our staff are granted access only in their respective fields and relevant day to day work. They are also required to maintain confidentiality after departure from the company via their contract of employment.

ChatMetrics.com developers treat stored data of customers with the highest level of security and care. Each piece of customer data is treated as personal and in need of standardized protection. We have deployed security policies which ensure safety of the data storage and transmission.

All ChatMetrics.com connections are encrypted with 256bit SSL protocol. There is no expiration date on the stored data. The data will remain on our servers even if a client does not extend his or her license. If you’d like to retrieve chats that you had with our support team, you can simply send us an email at team@chatmetrics.com, asking to retrieve all the data that we gathered at ChatMetrics.com on your behalf.

Encryption of Data at Rest

We use Amazon RDS which encrypts our databases using keys in the AWS Key Management Service (KMS). On a database instance running with Amazon RDS encryption, data stored at rest in the underlying storage is encrypted, as are its automated backups, read replicas, and snapshots. RDS encryption uses the industry standard AES-256 encryption algorithm to encrypt your data on the server that hosts your RDS instance.

Our data storage service (Amazon RDS) also supports Transparent Data Encryption (TDE). With TDE, the database server automatically encrypts data before it is written to storage and automatically decrypts data when it is read from storage.

Soluta autem maxime reiciendis neque rerum quia. Nostrum laudantium perferendis amet voluptatem vero voluptatem animi rerum veritatis. Aut omnis fuga ea neque ut odio assumenda temporibus. Ipsum quasi aut quod distinctio nemo. Dolorum hic porro consequatur et qui consectetur libero fugiat illo.

Encryption of Data in Transit

Encrypt communications between our application (chatmetrics.com) and our DB Instance using SSL/TLS. Amazon RDS creates an SSL certificate and installs the certificate on the DB instance when the instance is provisioned. The data is IP restricted to our dedicated domain ip address.

Domain used by ChatMetrics.com

To make sure your firewall is not blocking any ChatMetrics.com requests, please add the following domains to your firewall’s exception list.

  • chatmetrics.com
  • chat-application.com

ChatMetrics.com use the following versions of Transport Layer Protocol (TLS): 1.2

Security of Information

ChatMetrics.com ensures compliance with the following information related security and monitoring procedures:

  • Documented and defined security standards and procedures
  • Employee confidentiality agreement – contract of employment
  • Verification of employees who have access to customer data
  • Access to information granted only to employees who need to work with customer data or hosting servers
  • Access to customer data is limited within 12 hours of employee departure or relocation within ChatMetrics.com
  • Training on internal security policies and raising of security awareness as a day-to-day process
  • Physical security of the data center

Physical security ensured by data centers and hosting provided to and by ChatMetrics.com is achieved by:

Secure rooms with at least two access mechanisms, i.e., key-cards, man traps, security guards, and computer room badge-in

Authorized employees only are allowed physical access to the servers. 24/7 security at the location

Backups of customer data are stored on-site with limited access and at a securely controlled or commercial off-site location

The site guarantees additional protection such as uninterruptible power and fire suppression

Flawed components in the data center undergo DoD-approved “erase” or “wipe” procedure (if functionally possible) prior to physical destruction

Technical Controls

ChatMetrics.com supports technical controls to provide protection to its network, systems, and applications:

  • ChatMetrics.com utilizes professional facilities via a top tier hosting provider that protect customer data from external threats
  • ChatMetrics.com maintains individual accountability for employees that can access systems hosting customer data
  • ChatMetrics.com has documented user account/password management systems for employees with access to systems that are hosting customer data
  • ChatMetrics.com ensures that individual access to customer data is controlled, i.e., a diverse user name and password is required for each individual administrator
  • Customer data is compartmentalized to prevent unauthorized access and separated from the data of other customers
  • Access to customer data is protected by hardened passwords rotated on a 90 day basis
  • ChatMetrics.com’s data center has formal security policies and procedures in place that deal with viruses, other malware and related threats

To ensure protection of confidentiality, integrity, and availability of customer data, ChatMetrics.com meets the following usage criteria:

  • Each user is assigned a unique ID
  • User IDs and passwords can be edited by admin at any time
  • Passwords must be minimum 8 characters including at least 1 number, 1 letter and 1 special characters
  • The application and resulting access to data in the database has based-on-permission controls limiting access to only authorized customers
  • Each change of user login status is logged within each application
  • All logs are treated as confidential information and access to reports can be restricted using the permission system
  • Reporting of this information is available within each instance of ChatMetrics.com
  • If confidential data, personal data (i.e., names, addresses, phone numbers), or authentication information (i.e., passwords) is transmitted, ChatMetrics.com ensures security by employing 256bit SSL encryption between each component of the communications path
  • ChatMetrics.com’s security policy assumes customer data retention is permanent and is designed to that standard