Best of Breed Security
For complete peace of mind
At CRMnext, we know how important your data is for your business; this makes security
our primary concern. CRMnext was designed from ground up to deliver world-class
security. Apart from the software design, we have made heavy investments in our
state-of-the-art security infrastructure, strengthening our security measure, to
ensure that we back our offering by unparallel security.
What does it take to deliver such levels of security?
To ensure maximum security, we have concrete process in place backed by redundancy.
- Product designed with multi-level built-in security
- A dedicated team of security specialists.
- Round-the-clock security monitoring and protection
- Complete redundancy in the hosting infrastructure
- Near real-time assessments of emerging security threats and vulnerabilities
- Commitment to deliver the most secured online service
|
Security Levels
|
Description
|
|
Physical Security |
Our hosting infrastructure is collocated in Texas, at a facility that provides round
the clock military-grade security, biometric hand scanners, multi-stage power backups,
redundant data center air conditioners and a precision environment designed to keep
servers always up and running.
|
|
Network Security
|
The entire setup is protected using multiple firewalls and advance intrusion detection
software. These generate continuous logs that are analyzed to pick up patterns that
represent security threat.
|
|
Data Encryption
|
The data is encrypted using the strongest encryption products available in the Industry.
These include 128-bit SSL Certification and 1024 Bit RSA public keys.
|
|
User Authentication
|
Only authenticated users can access CRMnext.com. The username and password is encrypted
via SSL while in transmission. The session is maintained using encrypted cookies.
Further, session key is automatically scrambled and re-established in the background
at periodic intervals.
|
|
Application Security
|
Security has been built in at every level of the architecture, requiring multiple
validations on each request, to get to the data. A strong data ownership model prevents
CRMnext customer from accessing others data.
|
|
Deployment System Security
|
Once inside the network, port blocks, IP masquerading, non-routable IP schema, etc
are used to safeguard the deployment systems. Fixed schema rings and other propriety
technology further enhance security without limiting interoperability.
|
|
Operating System Security
|
CRMnext ensures maximum operating system security by essentially locking down all
the protocols, roles, users and processes not used by us. The production servers
use security token generator for password protection. We enforce a strict password
policy to ensure that passwords are strong and are not reused. Further, the security
team ensures that each system is kept at each vendors recommended patch level.
|
|
Database Security |
To ensure high database security, the production database has been physically separated
from the staging databases. The numbers of access points have been limited; the
operating systems restrict the IP addresses for requesting machines to our internal
network.
|
|
Server Management Security
|
Since data entered by our customers are crucial for their businesses, CRMnext.com
restricts access to production systems. Only key personals are provided access for
fixed time intervals to carry out system management, maintenance, monitoring, and
backups. All the activities are logged. No external managed service providers are
used.
|
|
Reliability & Backup
|
The deployment infrastructure has been designed to ensure no single point of failures.
This means, maintaining high levels of redundancy for our load balancers, web servers,
switches, network, RAID storage drives, etc. Apart from reliability, the entire
database is backed up every night, onto tapes that are stored in fire resistant
safes. Disaster recovery plans are in place to provide maximum continuity.
|
Note: The use of CRMnext service is subject to the terms and use of the service
agreement available through the CRMnext.com web site. Good security requires constant
changes and adaptation of new technologies, while guarding against emerging threats.
We may change our security infrastructure and/or this security datasheet from time
to time.