This Wartiva Security Addendum is incorporated into and made a part of the Wartiva Subscription Agreement or other written agreement between Wartiva and Customer that references this document (the “Agreement”) and any capitalized terms used but not defined herein shall have the meaning set forth in the Agreement.
Wartiva has implemented a comprehensive security, compliance and privacy management program under which Wartiva maintains industry standard physical, administrative, organizational and technical safeguards designed to protect the confidentiality, integrity, availability, and security of the Services and Customer Data, including the measures set forth herein (the “Security Program”). Wartiva regularly tests and evaluates its Security Program and may review and update its Security Program as well as this Wartiva Security Addendum from time to time including to take in account technological developments, provided, however, that such updates shall be designed to enhance and not materially diminish the Security Program.
1. IaaS and Hosting
a. IaaS Provider. Wartiva’s Platform is hosted on AWS.
b. Hosting location. Wartiva offers hosting in several locations including in the US, the EU and the UK.
2. Encryption
a. Encryption of Customer Data. Customer Data shall be encrypted by Wartiva in transit (TLS 1.2 or above) and at rest (AES-256).
b. Key Management. Wartiva utilizes AWS’ Key Management System (KMS) to encrypt Customer Data. Keys are rotated periodically and are stored only in the KMS in the region of the Customer’s Wartiva tenant.
3. Authentication, Authorization, and Credential Management.
a. User Authentication (Wartiva Employees). Wartiva enforces user authentication and authorization on Wartiva systems via multifactor authentication (“MFA”).
b. User Authentication (Customer using Wartiva). Wartiva supports SAML 2.0 compliant SSO applications, allowing customers to manage authentication for their own Wartiva tenant.
c. Secure Storage of Credentials. Wartiva uses managed authentication services (AWS Cognito for Wartiva’s software platform) to handle authentication and associated credential management, including encryption in-motion and at-rest for passwords and other forms of credentials. Cloud-native Key Management Systems, such as AWS KMS, are used to store other forms of access tokens and secrets.
d. Role-based Access Control (RBAC) for Wartiva Employees. Access to Wartiva information assets is restricted, and is granted to Wartiva employees and contractors in order to fulfill their duties on a need-to-use basis and following the least privilege principle. Wartiva employees and contractors are not granted access to any information asset that is not required by their work at Wartiva. Wartiva has defined various user roles, according to the positions and activities in the company. Each Wartiva employee and contractor is assigned one of these roles and receives access control privileges relevant to that role. Quarterly reviews for user access will be conducted and access will be immediately revoked for unrequired access.
e. Access to Customer Data. Wartiva personnel will not access Customer Data except (i) as reasonably necessary to provide the Wartiva Services under the Agreement; (ii) with Customer’s permission; or (ii) to comply with the law or a binding order of a governmental body.
f. Minimum password requirements. Wartiva shall follow the guidance provided by NIST 800-63B Digital Identity Guidelines to enforce password security controls, including length, complexity, re-use, lock-out, and use of multi-factor authentication. Passwords must never be stored in plain-text nor transmitted over unencrypted channels.
g. Session lifespan. Single-sign on sessions expire after 8 hours of inactivity with a maximum duration of 12 hours.
4. Workstation and Device Security
a. Session Lock out. Wartiva’s end-user devices are set to screen lock and require a password after 15 minutes of inactivity.
b. Workstation Security Controls. For access to Wartiva systems, Wartiva personnel must use Wartiva-issued laptops which utilize security controls that include, but are not limited to, (i) disk encryption, (ii) endpoint firewall, (iii) anti-malware and endpoint detection and response (EDR) tools, and (iv) vulnerability management tools in accordance with Section 8.1 (Vulnerability & Detection Management).
c. Anti-malware. Wartiva maintains anti-malware controls to automatically detect and prevent malicious files, user activity, and network activity on Wartiva workstations, within Wartiva’s e-mail, and within Wartiva’s corporate cloud storage solutions.
d. Workstation Management and Hardening. Wartiva utilizes system management technologies to ensure that all endpoints are appropriately configured, hardened, and patched following Wartiva’s technical procedures and applicable industry standards such as CIS Benchmarks.
e. Data Loss Prevention. Wartiva utilizes Data Loss Prevention (DLP) technologies to monitor and control sensitive information that is stored or accessed on systems. Wartiva workstations are restricted from using removable storage devices and media.
5. Cloud Infrastructure Security.
a. Separation of Environments. Wartiva’s cloud network is divided into two segregated network environments: The development or non-production network, and the production network. Each of these environments is segregated from the others and has its own privilege allocation and access control. There is no shared network, communication, or co-operation between the networks. Customer Data is never stored or accessed in non-production environments.
b. Infrastructure as Code. Wartiva’s cloud production environments are configured, provisioned, and managed through Infrastructure as Code (IaC), and subject to the controls defined in Wartiva’s Software Development Lifecycle (SDLC).
c. Remote Access. Wartiva enforces device, network, authentication, and resource-specific authorization controls to limit access to development and production environments. Wartiva does not automatically confer privileged access to any workstations or devices based on location.
d. Network Security. Wartiva utilizes cloud-native network security technologies, including network security groups, Web Application Firewalls, access gateways, application load balancers, and VPC configurations, to restrict ingress and egress traffic in cloud environments to the minimum sets of services and addresses required for business functionality.
e. Cloud Infrastructure Hardening. Wartiva utilizes technologies to ensure that cloud infrastructure is configured appropriately, hardened, and patched following Wartiva’s technical procedures and applicable industry standards such as CIS Benchmarks.
f. Anti-malware. Wartiva utilizes cloud-native security services to detect and respond to potentially malicious activity on its cloud-hosted workloads or networks.
6. Monitoring and Logging.
a. Logging. Wartiva maintains security auditing and logging capabilities for the infrastructure, SaaS applications, and cloud services that support its corporate, development, and production environments in accordance with Wartiva’s Information Security Policies. The use and activity of Wartiva information assets is logged and audited for suspicious activity. Wartiva preserves security-related logs for a minimum of 3 months unless otherwise specified in its security policies and procedures.
b. Detection and Response Operations. Wartiva uses Security Information Event Management (SIEM), Detection, and Alert Notification technologies to centralize and analyze logs, apply detection criteria, and escalate and route events to the appropriate security teams.
7. Security in the development process.
a. SDLC. Software development in Wartiva is performed according to Wartiva’s Change Management & Software Development Life Cycle (SDLC) procedures.
b. Security Reviews. Wartiva conducts security reviews for significant changes, such as major new product features or changes that impact Wartiva’s security posture, during the design and development process.
c. Peer Reviews. Code changes must undergo secondary review and approval before being promoted to production.
d. Security Testing within the SDLC. Wartiva uses security technologies to automatically scan for vulnerabilities, exposed secrets, and code security risks as part of the CI/CD pipeline.
8. Vulnerability Detection & Management.
a. Vulnerability Detection & Management. Wartiva shall maintain a continuous vulnerability management process across its corporate and production environments to ensure that vulnerabilities and other threats are quickly identified, prioritized, and remediated. This includes carrying out internal vulnerability tests daily and external vulnerability tests regularly (at least quarterly). Vulnerabilities shall be remediated according to Wartiva’s Vulnerability Management Policy which shall meet or exceed industry standards. Wartiva uses the Common Vulnerability Scoring System (CVSS) v3.1 and National Vulnerability Database (NVD) ratings as guidelines for patch prioritization and scheduling.
b. Penetration Testing. Wartiva shall engage one or more independent third parties to conduct penetration tests of the Service at least annually and upon major changes to the Services. Wartiva will provide summary results of penetration tests to Customer upon written request.
9. Administrative & Organizational Controls.
a. Personnel Security. All prospective Wartiva employees go through pre-employment reference and/or background checks, according to the local HR policies and applicable laws.
b. Personnel Agreements. All Wartiva employees and contractors are required to sign a contract which includes a confidentiality obligation and are provided with Wartiva’s security policies, including Wartiva’s Acceptable Use Policy, when their work commences. Any change in an employee's position in Wartiva or change in his or her access privileges immediately affects the employee's access via the centralized access control system.
c. Personnel Training. All Wartiva employees are required to complete security and privacy awareness training during onboarding and on at least an annual basis.
d. Vendor Risk Management. Wartiva maintains a vendor risk management program, which includes a compliance, security, and privacy review for every third-party used in the provision of the Services and/or with access to Customer Data. The results of the risk assessment are reviewed by the security, legal and privacy team to ensure the third party maintains security measures consistent with the measures hereunder.
10. Physical & Environmental Controls.
a. Cloud Environment Data Centers. Wartiva only utilizes leading cloud providers who shall be required to have a SOC 2 Type II annual audit and ISO 27001 certification, or industry recognized equivalent frameworks.
b. Wartiva Corporate Offices. Wartiva's employees and subcontractors in each of Wartiva’s offices are subject to Wartiva's physical minimum-security requirements which include use of CCTV with a defined retention period in accordance with applicable laws, badge only access with regular access reviews and requirements for visitors to be logged and accompanied by Wartiva authorized personnel.
11. Security Incident Notification and Response.
a. Wartiva shall maintain a formal documented Information Security Incident Management Program designed to provide an effective and consistent process for managing security incidents.
b. Security Incident notification. In any event of a reasonably suspected or successful unauthorized access, use, disclosure, modification, or destruction of Customer Data (“Security Incident”), Wartiva will notify Customer within 48 hours of becoming aware of the Security Incident and shall promptly take reasonable steps to contain, investigate, and mitigate such Security Incident. Wartiva shall provide Customer with assistance and information as reasonably required by Customer in order to fulfil its legal obligations.
c. Security Incident Reporting and Response. Security Incidents are reported to Wartiva’s Chief Information Security Officer (CISO). The CISO acts according to Wartiva's Incident Response Plan in classifying, handling, documenting, and reporting any incident. Customer may request a copy of Wartiva’s Incident Response Plan.
12. Backup, Business Continuity & Disaster Recovery
a. Business Continuity and Disaster Recovery Plan. Wartiva maintains industry standard business continuity and disaster recovery procedures, as further described in Wartiva’s Enterprise Resilience Policy (“BCDRP”), and will implement these procedures to minimize the impact of events, whether related to technology or operational failures, that may affect Wartiva’s ability to provide the Services. Wartiva’s RTO shall not exceed 24 hours.
b. Testing of BCDRP. Wartiva shall conduct testing of its BCDRP at least annually and shall make the results of such testing available to Customer upon written request.
c. Backups and Disaster Recovery. Wartiva leverages multiple Amazon services to backup Customer Data on both daily and monthly schedules. Each Customer tenant is allocated a disaster recovery tenant in a geographically distinct area. Where possible, Wartiva will use a disaster recovery region in the same jurisdiction as the main data center. Wartiva also keeps full and incremental backups of critical corporate data and logs in geographically distinct datacenters.
13. Shared Responsibility. Without derogating from Wartiva’s obligations hereunder, Customer acknowledges that it is responsible for implementing, running and managing the Platform on a day-to-day basis. In addition, Customer acknowledges and agrees that it has obligations with respect to the security of the Customer Data and the Services. Customer’s responsibility includes but is not limited to: (i) the security of endpoints and network environments it owns, operates, and connects to or installs Wartiva on, and for configuration of its instance(s) of the Wartiva Platform; (ii) provisioning Permitted Users with access to Customer’s instance of the Wartiva Platform, including: (a) managing instance-level administrators and other user privileges; (b) deauthorizing Permitted Users who no longer need access; (c) provisioning and configuring service account or API access; (d) enabling integrations with customer-owned or third-party technologies; and (e) ensuring that all Permitted User’s keep all Wartiva credential’s confidential; and (iii) updating any Wartiva provided software upon Wartiva’s announcement of such updates. Wartiva may update the Shared Responsibility from time to time, provided that any such update will not materially degrade the Parties’ rights and obligations thereunder. Customer agrees to notify Wartiva upon becoming aware of any reasonably suspected unauthorized access to the Platform.