Last Updated: 01-Feb-2025
Security Compliance at Acriotech
At Acriotech, security is not a feature — it is the foundation. Every system we build, every line of code we ship, and every piece of infrastructure we operate is designed with a security-first mindset. Our enterprise clients trust us with their most sensitive data, and we take that responsibility with the utmost seriousness.
1. Our Security Philosophy
Acriotech operates under the principle of Defense in Depth — a layered security strategy that ensures no single point of failure can compromise the integrity or confidentiality of our systems. We combine technical controls, administrative policies, and continuous human oversight to create a resilient security posture.
Our security program is aligned with the NIST Cybersecurity Framework (CSF 2.0), covering five core functions: Identify, Protect, Detect, Respond, and Recover. This is not a checkbox exercise — these functions drive our actual engineering and operational processes day-to-day.
Annual third-party audit verifying security, availability, and confidentiality controls.
Internationally certified Information Security Management System (ISMS).
PHI-safe infrastructure for healthcare clients with signed BAAs available.
All web applications are hardened against the OWASP Top 10 vulnerabilities before release.
2. Infrastructure & Cloud Security
All Acriotech production systems are hosted on Tier-1 cloud providers (AWS, GCP, Azure) operating out of certified data centers with SOC 1, SOC 2, and ISO 27001 accreditations. We enforce strict network segmentation using VPCs, private subnets, and firewall rules to isolate production, staging, and development environments.
- Zero Trust Network Architecture: Every internal service-to-service call is authenticated using mutual TLS (mTLS). We do not operate a flat, trusted internal network.
- Secrets Management: All API keys, credentials, and tokens are stored in Hardware Security Module (HSM)-backed vaults (HashiCorp Vault or AWS Secrets Manager). Hard-coded credentials are prohibited and automatically detected in CI/CD pipelines.
- Immutable Infrastructure: Production servers are never patched in place. All changes are applied by replacing infrastructure using versioned, tested Infrastructure-as-Code (Terraform/Pulumi) templates.
- DDoS Mitigation: All public-facing endpoints are protected by managed DDoS mitigation services with automatic traffic scrubbing and geo-blocking capabilities.
3. Encryption Standards
Acriotech mandates encryption at every layer of the data lifecycle:
| Layer | Standard | Details |
|---|---|---|
| Data at Rest | AES-256-GCM | All databases, file stores, and backups are encrypted at the block and file level. |
| Data in Transit | TLS 1.3 | All communication channels enforce TLS 1.3. Legacy TLS 1.0/1.1 is disabled globally. |
| Database Fields | AES-256 (Application-level) | PII fields (SSN, payment data, health records) are encrypted at the application layer before database storage. |
| Key Management | HSM-backed KMS | Encryption keys are rotated annually and stored in FIPS 140-2 Level 3 certified HSMs. |
| Backups | AES-256 + HMAC-SHA256 | All backups are encrypted and their integrity is verified using HMAC before restoration. |
4. Vulnerability Management & Penetration Testing
Acriotech operates a continuous vulnerability management program covering our infrastructure, applications, and third-party dependencies:
- Automated Scanning: Every code commit triggers automated SAST (Static Application Security Testing) and dependency vulnerability scans via integrated CI/CD pipelines. Critical or high-severity CVEs block deployment automatically.
- DAST in Staging: Dynamic Application Security Testing (DAST) tools run against every staging deployment to detect runtime vulnerabilities including injection flaws, broken authentication, and XSS.
- Annual Penetration Testing: We engage independent, CREST-certified security firms to conduct comprehensive black-box and gray-box penetration tests annually across our entire attack surface.
- SLA for Remediation: Critical (CVSS 9.0+) vulnerabilities are patched within 24 hours, High (7.0-8.9) within 7 days, Medium (4.0-6.9) within 30 days.
- Bug Bounty Program: We operate a responsible disclosure program. Security researchers who discover vulnerabilities and disclose them in good faith are publicly acknowledged and rewarded.
5. Access Control & Identity Management
Acriotech enforces the principle of Least Privilege across all systems. Every employee, contractor, and automated system is granted only the minimum permissions required to perform their function.
- Multi-Factor Authentication (MFA): MFA is mandatory for all employees accessing internal systems, cloud consoles, code repositories, and production infrastructure. Hardware security keys (FIDO2/WebAuthn) are the required second factor for privileged access.
- Single Sign-On (SSO): All internal tooling is integrated via a centralized Identity Provider (IdP). When an employee leaves, their access is immediately revoked from all connected systems through a single deprovisioning action.
- Just-In-Time (JIT) Access: Engineers do not have standing access to production databases. Production access is granted on a time-limited, request-and-approval basis with full audit logging of all actions taken.
- Quarterly Access Reviews: All access rights are reviewed quarterly. Unused permissions are revoked automatically.
6. Incident Response
Acriotech maintains a formally documented Security Incident Response Plan (SIRP) that is tested via tabletop exercises bi-annually. Our incident lifecycle follows these stages:
24/7 SIEM monitoring alerts our on-call Security Operations Center (SOC) team. All alerts are triaged within 15 minutes.
Automated playbooks execute initial containment (e.g., account lockout, network isolation) within minutes of confirmed incident classification.
Root cause is identified, affected systems are rebuilt from verified clean images, and integrity checks are run before traffic restoration.
Affected enterprise customers are notified within 72 hours of breach confirmation, meeting GDPR and contractual SLA obligations.
A formal post-mortem is conducted within 5 business days. Findings and remediation actions are documented and shared with affected parties upon request.
Security Inquiries & Reporting
To request our SOC 2 Type II report or ISO 27001 certificate, or to report a security vulnerability, contact our Security team at security@acriotech.com. We respond to all security inquiries within one business day.