Security & data protection

Security & data protection

SECURITY OVERVIEW

Security starts with trust

We know your data is sensitive. That’s why we combine enterprise- grade security features with regular audits to ensure that you’re always protected.
Compliance

Compliance

We ensure rapidbee meets industry-standard compliance.
Learn More
infrastructure

Infrastructure

We use industry best practices to provide rapidbee services.
Learn More
Personnel

Personnel

We ensure every rapidbee employee is vetted and trained.
Learn More
App Development

App & development

Our product is built with security and quality top of mind.
Learn More

Compliance

We comply with global data protection and security frameworks

GLobal data protection

SOC 1 & SOC 2 Type II Certified

rapidbee SOC 1 and SOC 2 Type II report covers the trust services categories of Security, Confidentiality, and Availability, and is audited annually.

HIPAA Certified

rapidbee entire team is HIPAA trained and certified every two years.

GDPR Compliance

We comply with GDPR as a data processor, and manage the transfer data via Standard Contractual Clauses.

CCPA Compliance

We ensure policies, processes, and controls comply with CPRA and CCPA requirements.

Data & infrastructure security

We're built to secure your most sensitive data

Personal security

Secure infrastructure provider

We host all of our data in physically secure, U.S.-based Amazon Web Services (AWS) facilities that include 24/7 on-site security, camera surveillance, and more.

Data encryption in transit & at rest

All data sent to or from rapidbee is encrypted using TLS, and all customer data is encrypted using AES-256.

Data redundancy and resilienc

rapidbee infrastructure has been designed to be fault tolerant. All databases operate in a cluster configuration and the application tier scales using load balancing technology that dynamically meets demand.

Data Backup and Replication

rapidbee Database is constantly replicated in multiple AWS Regions across the US. The data is backed up every day and a copy is kept for 90 days.

Strict access controls

Access to all rapidbee  systems is managed through our identity provider, which automates user provisioning, enforces 2FA, and logs all activity.

Server security and monitoring

All servers are configured using a documented set of security guidelines, and images are managed centrally. Changes to the company’s infrastructure are tracked, and security events are logged appropriately.

Personnel security

We hold our employees to the highest standards

Most sensitive data

Formal security policies and incident response plan

rapidbee maintains a set of comprehensive security polices that are kept up to date to meet the changing security environment. These materials are made available to all employees during training and through the company’s knowledge base.

Strict onboarding and off boarding process

Every new hire must pass a thorough background check and attend a “Legal and Security” training course, as well as an InfoSec training course once a year. We instantly disable departing employee’s devices, apps, and access during offboarding via rapidbee IDM and MDM products.

Continuous security training

The rapidbee Security Team provides continuous education on emerging security threats, performs phishing awareness campaigns, and communicates with employees regularly.

Office security

rapidbee manages visitors, office access, and overall office security via a formal office security program.

App & development

Our developers keep security top of mind

keep security

Penetration testing and bug bounties

We regularly run internal pen tests and partner with reputable security firms to run external pen tests. Additionally, our bug bounty program allows anyone to test our system and report bugs.

Application monitoring and protection

All app access is logged and audited. We also use a wide variety of solutions to quickly identify and eliminate threats, including a Web App Firewall (WAF) and Runtime App Self Protection Agent (RASP).

Development and change management process

Code development is done through a documented SDLC process, and every change is tracked via GitHub. Automated controls ensure changes are peer-reviewed and pass a series of tests before being deployed to production.

Ready to make a change?

See the rapidbee process automation platform in action, and learn more about the white-glove service our customers love.
Get a Demo

Stay connected to rapidbee.

Get our latest blogs, updates, and industry news delivered straight to your inbox.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.