Compliance
The essensys Platform complies with several key regulatory and industry standards:
ISO Standards
ISO 27001 – We are consistent with ISO 27001 and are working towards full certification for our information security management system (ISMS)
ISO 27017 and ISO 27018 - Our certification efforts are aligned to these cloud security standards
ISO 9001 – We maintain consistency with this quality management standard
SOC Reports
SOC 1 (SSAE 18 / ISAE 3402), SOC 2, and SOC 3 audits - Our information security control environment undergoes independent evaluation through these Service Organization Control reports
Infrastructure Security
essensys Platform uses enterprise-grade infrastructure provided by AWS (Amazon Web Services), which is SSAE16, ISO27001, and PCI-DSS accredited, ensuring comprehensive physical, network, data, and user security
Additional Compliance
GDPR compliance for data protection
Regular security assessments by internal personnel and third parties, including infrastructure vulnerability and application security assessments on at least an annual basis
Hosting
essensys Platform use enterprise-grade infrastructure and solutions provided by AWS (Amazon Web Services). The solution uses Regional based Multi Availability Zones ensuring High Availability in 3 different regions around the World. AWS is SSAE16, ISO27001 and PCI-DSS accredited, ensuring physical, network, data, and user security.
Backup Arrangements
essensys Platform makes use of 2 database engine types named RDS PostgreSQL and DynamoDB
Frequency: Full backups are taken daily, RDS PostgreSQL log backups are taken every 5 minutes and DynamoDB log backups are taken every minute.
Method: Backups are automated and fully managed by AWS.
Retention Period: The backup and log retention period is 35 days, after which the backups are discarded.
Storage Location: The backups are encrypted and stored in AWS S3, to which only a limited number of people have access.
Disaster Recovery Capability
Failover testing is fully managed by AWS.
Our RTO (Recovery Time Objective) for RDS PostgreSQL is 5 minutes and DynamoDB is 30 minutes.
Our RPO (Recovery Point Objective) for RDS PostgreSQL is 5 minutes and DynamoDB is 1 minute.