Security
Academy Of Mine is committed to protecting your information and maintaining the highest standards of security for our platform and services. We employ a variety of security technologies and measures designed to protect information from unauthorized access, use, or disclosure. Our platform uses industry-standard security practices to ensure the confidentiality, integrity, and availability of your data. We maintain a comprehensive information security management system aligned with ISO 27001 standards.
Data Protection & Encryption
Payment Information: We do not store sensitive payment information such as credit card numbers on our servers. AOM only connects with payment gateways through tokenization methods, ensuring no payment or financial information touches AOM servers. Our payment processors (including Stripe) are PCI Compliant and maintain bank-grade encryption.
Data Encryption: All data transmitted between your device and our servers is encrypted using industry-standard encryption protocols. We use secure connections (HTTPS/TLS) to protect data in transit. Database encryption options are available for enterprise clients.
Password Security: All stored passwords are one-way hashed with a salt using bcrypt hashing, ensuring passwords are never stored in plain text.
Infrastructure & Hosting
Cloud Providers: AOM uses a combination of cloud providers including Amazon Web Services (AWS), DigitalOcean, and Hivelocity.net. We do not operate our own data centers, leveraging industry-leading cloud infrastructure providers.
Data Centers: Our servers are located across the United States in New York, New Jersey, and Florida, with additional regions available for European and Asian clients upon request. All data centers are Tier IV facilities with 24/7/365 staffing and redundant power systems.
Single-Tenant Architecture: Each customer receives their own instance of applications and databases. Enterprise customers also receive separate dedicated servers, ensuring complete data isolation and security.
Access Controls & Authentication
Role-Based Access Control (RBAC): We support role-based access control for both end-users and system administrators, ensuring users only have access to the data and functions necessary for their roles.
Single Sign-On (SSO): Our platform supports OAuth2/SAML-based Single Sign-On (SSO) and integrates with services like Okta and Auth0. Active Directory integration is available for enterprise clients through customizations.
Multi-Factor Authentication: Google Authenticator and 2-Factor Authentication (2FA) are available for enterprise clients to provide an additional layer of security.
Password Management: We follow the latest NIST security guidelines, which emphasize password length as the primary defense against brute force attacks. The system checks passwords against known breached password databases and employs rate limiting to prevent brute force attacks. Passwords are never visible in administration modules.
Remote Access: Employee access to customer data remotely is only permitted with authorized and audited access controls in place.
Network Security
Web Application Firewall (WAF): AOM utilizes Cloudflare.com as a third-party WAF provider to protect against web-based attacks and threats.
Intrusion Detection: We perform intrusion monitoring through a combination of internal systems and third-party services to detect and respond to security threats.
Network Segregation: Databases are segregated from front-end systems (web and application servers), providing an additional layer of security.
Vulnerability Management
Vulnerability Scanning: Our applications undergo regular vulnerability assessments performed by third-party security companies. Applications are scanned for vulnerabilities prior to new releases to ensure security is maintained throughout the development lifecycle.
Security Testing: For enterprise clients, we allow customers to perform their own security testing of our systems and applications at mutually agreed upon times.
Data Backup & Recovery
Backup Schedule: All data is backed up on multiple off-site locations, including Amazon AWS S3, on a nightly basis. Both application code and databases are backed up remotely and off-site.
Backup Retention: AOM retains the last 30 days of data backups, with hourly backups maintained for the last 24 hours.
Business Continuity: We maintain both Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) to ensure service availability and data recovery capabilities.
Data Export: Customers can extract full backups of their data at any time. Upon contract completion, all data remains available within 60 days of contract termination.
Physical Security
Physical Security Controls: We maintain physical security controls and policies. Employees are only allowed to take home customer data on authorized company devices such as laptops with restricted access.
Data Center Security: All data centers where customer data resides are managed by our cloud providers, who maintain SOC 2 Type 2 certifications and implement comprehensive physical security measures.
Your Responsibility
You are responsible for ensuring your website is secure and your passwords are protected at all times. Also, you are responsible to ensure that your password strength for your account is reasonably high and weaker passwords can be targeted by hackers which is not in our control.
Certifications
Academy Of Mine maintains the following security certifications:
ISO/IEC 27001
Academy Of Mine is certified to ISO/IEC 27001, demonstrating our commitment to information security management. ISO/IEC 27001 is an internationally recognized standard that specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
Our Certifications:
- ISO/IEC 27001:2022 (International)
- NF EN ISO/IEC 27001:2023 (Europe)
This certification validates that we have implemented comprehensive security controls and processes to protect information assets and manage security risks effectively. Our ISMS covers all aspects of information security, including policies, procedures, risk management, and continuous improvement processes.
Security Documentation
For detailed information about our security practices, encryption standards, compliance requirements, and answers to common security questions, please download our Security Vendor Assessment document.
Contact Us
If you have any questions or concerns about security, please contact us at info@academyofmine.com.