Security Practices
At WASViking, security is embedded in every layer of our platform. Below is an overview of the practices we implement to protect data and ensure service integrity:
Data Encryption
- Data in transit is protected using TLS 1.2 or higher.
- Customer data stored in Amazon RDS and MongoDB Atlas is encrypted at rest. Managed backups and encrypted snapshots are configured for both database platforms, with recovery capabilities available when restoration is required. Connectivity between the WASViking AWS environment and MongoDB Atlas uses private network connectivity through AWS PrivateLink.
- Stored credentials, tokens, MFA secrets, and integration keys receive an additional layer of application-level encryption. Uploaded mobile application binaries are stored with server-side AES-256 encryption.
Account Authentication
Access to WASViking customer and partner environments is protected by additional authentication controls. Users are required to complete the security verification steps presented by the platform, which may include an email security code at sign-in, authenticator-based two-factor authentication, or authentication through an approved identity provider.
Authentication requirements may vary according to the account, organization settings, enabled identity provider, and security policies applied by WASViking.
Access Control
- Role-based access control (RBAC) with least-privilege principles and tenant isolation.
- Security-relevant actions, including authentication, permission changes, scan lifecycle, data deletion, and sensitive-data reveals, are recorded in a tenant-scoped audit log. Selected high-integrity events carry tamper-evident protection.
Secure Infrastructure
- Hosted on Amazon Web Services (AWS) behind Cloudflare (WAF, TLS, DNS), with network segmentation (VPC) and least-privilege access (IAM).
- Security updates and patches are applied regularly across the environment.
Development Practices
- Secure Development Lifecycle (SDLC) with code reviews.
- Dependency management with vulnerability monitoring.
- Secrets and credentials are managed securely.
Monitoring & Response
- Automated monitoring and alerting across the platform.
- Incident response procedures in place.
- We use the WASViking platform to continuously test our own services.
Sensitive Data Handling (Exposure Intelligence)
WASViking includes features designed to identify potential exposure of sensitive data, such as credentials, email addresses, and related security indicators.
- Sensitive fields are masked by default and require explicit user action to be revealed;
- All access to sensitive data may be logged and audited for security and abuse prevention;
- Access is restricted based on role-based permissions (RBAC) and least-privilege principles;
- Data is processed solely for legitimate security purposes, including risk identification and remediation;
- We do not enrich, correlate, or use such data for profiling or marketing purposes.
Customers are responsible for ensuring that access to sensitive data is limited to authorized personnel and complies with applicable data protection and privacy laws.
Compliance
- Practices aligned with GDPR, LGPD, and CCPA.
- Data Processing Agreement (DPA) available upon request.
Contact Information
For detailed questions, contact our team:
WASViking LLC
Orlando, FL, USA
[email protected]