Why is data security critical for your Continuous Testing Platform?
Topics
As part of your end to end functional testing on pre-production and production servers, you might be using your customer’s critical data which includes critical data line credentials, phone numbers, names, etc.
Also, you might be adding all the critical test scenarios to describe how the application is being tested, which could expose potential vulnerabilities of your application. We understand that we must ensure the privacy and security of your data to remain a priority to protect against breaches.
Not just that, we believe that everything you add in Testsigma is highly confidential to your organization. We owe our customers the promise that all of the data will be handled safely and securely and will never be shared without your consent.
Here is how we secure the platform
At Testsigma, we take data integrity and security very seriously. We are at standby to safeguard the reputation of your business, establishing as a brand that people can trust with their confidential data.
Our facilities, processes, and systems are reliable, robust, and third-party tested. We continuously look for opportunities to make improvements and give you a highly secure, scalable system for your continuous testing requirements.
Here are some of the things that we do continuously to secure the platform
Physical and Network security
Testsigma uses Amazon's AWS platform and infrastructure. Testsigma employees do not have any physical access other than designated employees with administrative privileges to our production environment.
Here are more details about the security setup of AWS.
Cloud security is the highest priority at AWS. As an AWS customer, we are benefitted from a data center and network architecture built to meet the requirements of the most security-sensitive organizations.
Amazon has many years of experience in designing, constructing, and operating large-scale data centers. This experience has been applied to the AWS platform and infrastructure. AWS data centers are housed in nondescript facilities, with military-grade perimeter control berms. Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, state of the art intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication no fewer than three times to access data center floors. All visitors and contractors are required to present identification and are signed in. They are also continually escorted by authorized staff.
In addition to physical security, being on AWS platform also provides us with significant protection against traditional network security issues on the infrastructure including:
- Distributed Denial Of Service (DDoS) Attacks
- Man In The Middle (MITM) Attacks
- Port Scanning
- Packet sniffing by other tenants
Testsigma obtains the SOC 1 and SOC 2 report from AWS for the services rendered by them and validates the same for the effectiveness of the opinion of the third-party auditors.
Administrative Operations
At Testsigma, we use two-factor authentication to grant access for our administrative operations, including both infrastructure and Testsigma service. Administrative privileges are restricted to limited employees. Additionally, both application level roles and AWS roles are used to ensure only the required operations are allowed for specific users.
Any administrative access is automatically logged and mailed to our internal security team. Detailed information on when/why the operations are carried out is documented and notified to the security team before performing any changes in the production environment.
Host Security
SSH keys are required to gain console access to our servers and each login is identified by a user. All critical operations are logged to a central log server and our servers can be accessed only from restricted and secure IPs.
Hosts are segmented and accesses are restricted based on functionality. That is, application requests are allowed only from AWS ELB and database servers can be accessed only from application servers.
Application Security
- Secure Access
Testsigma’s application servers can be accessed only via HTTPS. We use industry-standard encryption for data traversing to and from the application servers. - XSS
All user input is properly encoded when displayed to ensure XSS vulnerabilities are mitigated. - CSRF
All POST requests are checked for CSRF token before processing the request. - SQL Injection
We use prepared statements for database access to avoid SQL Injection attacks. - Encrypted Data Storage
We do not store sensitive card details on any Testsigma network. The keys for various third-party services (like payment gateway) are stored in our database in encrypted form.
Vulnerability Scanning & Patching
We periodically check and apply patches for third-party software/services. As and when vulnerabilities are discovered, we apply the fixes. We do periodic vulnerability scanning using the services of an authorized QSA.
Testsigma performs the VAPT assessment on a quarterly basis.
Data Storage & Redundancy
We use Amazon's RDS for our database. The automated backup feature is configured for RDS. We backup data up to 21 days. We have configured Amazon RDS in Multi-AZ which provides enhanced availability and durability. Each AZ runs on its own physically distinct, independent infrastructure, and is engineered to be highly reliable. Know more.
Monitoring
We use both internal and multiple external monitoring services to monitor Testsigma. Our monitoring system will alert the Operations & Security Team through emails and phone calls if there are any errors or abnormalities in the request pattern.
Disclosure
We are working continuously to make our system secure. If you find any security issues, please notify us at security@testsigma.com. We will make sure it is fixed and updated at the earliest.
You can be confident that we take security as our highest priority to protect data and confidentiality of client information.