Do you think you have what it takes to ship software? I’ll let you in on a secret: it’s not easy and takes a lot of effort—but...
Keeping your data secureThomas Fuchs
Here’s what we do at Freckle to keep your data safe and sound:
Redundant Protection Against Data Loss
Freckle uses state-of-the-art RAID 10 data storage. We make hourly backups of Freckle’s databases and daily (full image) backups of Freckle’s servers. These backups are saved and encrypted on storage services off-site, then systematically tested for integrity. Hourly backups are saved for several months. Monthly backups are stored long-term. We maintain live copies of all our log files off-site. Sensitive data like passwords or credit card numbers are never logged.
Your Credit Card Data is Safe
Freckle does not transmit or store your credit card information on our servers. However, we fully comply with the PCI DSS in the interest of keeping all data secure. This means your credit card data is securely submitted directly from your browser (without touching our servers) to a leading, fully PCI-compliant payment gateway provider. Freckle is regularly scanned for known vulnerabilities by a principle provider of PCI compliance certification.
Always-on Secure Connections
Freckle uses Always-on secure SSL connections for all accounts. We use a 2048-bit key and score an A+ on the Qualys SSL Labs test (as of 5/2015). We have Perfect Forward Secrecy and Strict Transport Security enabled on supported browsers. Our session and “remember me” cookies use the secure and HTTP only flags. We frequently and consistently review our SSL configuration and make appropriate updates in the unlikely case new SSL vulnerabilities are discovered.
Up-to-Date Infrastructure and Patches
Freckle’s infrastructure maintains peak performance with regularly scheduled security updates and by promptly applying any patches that are recommended for immediate role out. Strict measures are in place to ensure that maintenance access to our servers is only allowed on a case-by-case basis. To fortify this, our network is locked down with firewalls. For even more added security, the Freckle application is hosted on a separate server and network, from our support system and our main site (http://letsfreckle.com).
Freckle is hosted by Rackspace, a globally leading managed cloud company. Rackspace provides excellent, state-of-the-art physical security, including two-factor biometric authentication, role-based secure sub-areas, closed-circuit 24x7x365 video surveillance, and physical perimeter defense measures. These security structures reinforce our redundant systems for climate control, conditioned power, routing, and internet connectivity.
Monitoring and Fast Response
Freckle mobilizes redundant, world-wide monitoring services to supervise our 24x7x365 infrastructure. Our developers are instantly made aware of any errors, slow-downs, or other abnormalities by automatic alarms. Our team pro-actively runs automated scans (provided by trusted 3rd-party compliance services) of our servers for security issues and PCI compliance. Should we detect issues with your account, we will immediatly contact the account owner by email.
Your Data is Yours, Always
Please send urgent and/or sensitive security reports directly to [email protected]. Use our public key to send sensitive data to us. Please let us know how we can securely contact you.
Please send questions or concerns to [email protected].