Advanced service. Advanced technology.
Cartegraph utilizes Amazon Web Services (AWS), the top data center infrastructure in the nation to host its cloud products. It’s designed for high-density cloud computing environments. All data is encrypted and de-duplicated between the user and the data center through multiple distribution paths to ensure reliable, uninterrupted access 24 hours a day, seven days a week, 365 days a year.*
AWS operates under a shared security responsibility model, where AWS is responsible for the security of the underlying cloud infrastructure and Cartegraph is responsible for securing workloads deployed in AWS.
AWS Compliance Program
SOC 1/SSAE 16/ISAE 3402 (formerly SAS 70)
- SOC 2
- SOC 3
- DOD CSM Levels 1-5
- PCI DSS Level 1
- ISO 9001 / ISO 27001
- FIPS 140-2
- MTCS Level 3
Physical and Environmental Security
- Geographically diverse locations able to weather nearly any possible incident
- Fire detection and suppression equipment to reduce risk
- Redundant electrical power systems with Uninterruptible Power Supply (UPS) units and generators
- Climate controlled to maintain constant operating temperature for servers
- Preventative maintenance performed regularly to maintain the continued operability of equipment
- Detailed decommissioning for end-of-life storage devices
Business Continuity Management
- Systems designed to tolerate failures with minimal customer impact
- Data centers built in clusters in various global regions
- All data centers online and serving customers
- Secure network architecture, including firewall and other boundary devices
- Limited number of strategically placed secure access points to allow for comprehensive monitoring
- Transmission protection via HTTP or HTTPS using Secure Sockets Layer (SSL),
For more information, visit AWC Cloud Security or refer to Amazon Web Services: Overview of Security Processes
*Server maintenance is performed at regular intervals during commercially reasonable times. Customers experience limited or no server connectivity while these events occur.
Cartegraph follows a meticulous set of protocols and procedures to protect your data at all times. And if your security needs evolve or change, we’ll do whatever is necessary to fully meet them.
Firewall and Systems Security
We use a diverse series of firewalls to prevent unauthorized access. Those same firewalls ensure secure, fluid connection between authorized users and the Cartegraph Cloud.
Backups and Data Recovery
If a restore is necessary, Cartegraph recovers your data quickly and efficiently — we go to great lengths to ensure it:
- Daily backups as virtual full images able to be quickly recovered
- Data de-duplication reduces daily backup data, optimizing WAN bandwidth
- System verifies data recoverability and server integrity daily
- Nightly data encryption and backup
- Backups and snapshots are retained for 14 days
Crisis Management / Disaster Recovery
In the event of a disaster or serious issue, our Crisis Management Procedure goes into immediate effect:
- 24/7/365 Remote Hands for technical support and tactical response.
- Disk-to-disk replication (eliminates tape shipment and provides encrypted transmissions)
- The Data Center experts function as an extension of IT
- One-Step Recoveries
- We quickly assess and identify the issue
- We dedicate our people and resources to resolving the issue as quickly as possible
- We provide you regular updates on the progress of the issues until it’s resolved
Security Patch Management
We make it a priority to safeguard users against problems, threats, and vulnerabilities. By constantly monitoring, testing, and implementing the latest security patches, we’re able to continually improve our cloud and protect your data. Furthermore, we’re compliant with PCI-DSS v2.0, SOX, FEDRAMP HIPAA / HITECH guidelines, are received an annual audit using SSAE-16 SOC I.
Keeping your system tuned and your data safe.
Regular Scheduled Maintenance
Prior to any scheduled maintenance, we’ll reach out and let you know how long we expect the maintenance to take and which, if any, parts of your hosted solution are affected. And we’ll always do our best to schedule maintenance during times that don’t interfere with your day-to-day operations.