TipHaus Commitment to Security
Section 1: Application Security
1. Data is encrypted in transit with TLS 1.2. Data is encrypted at rest with AES.
2. Independent third-party penetration, threat, and vulnerability testing.
3. User access controls with single sign-on and MFA.
Section 2: Our policies are based on the following foundational principles:
1. Access should be limited to only those with a legitimate business need and granted based on the principle of least privilege.
2. Security controls should be implemented and layered according to the principle of defense-in-depth.
3. Security controls should be applied consistently across all areas of the enterprise.
4. The implementation of controls should be iterative, continuously maturing across the dimensions of improved effectiveness, increased auditability, and decreased friction.
Section 3: Continuous Security Commitment
1. Penetration Testing
2. We perform an independent third-party penetration test at least annually to ensure that the security posture of our services is uncompromised.
3. Security Awareness Training
4. Our team members are required to go through employee security awareness training covering industry standard practices and information security topics such as phishing and password management.
5. Third-Party Audits
Our organization undergoes independent third-party assessments to test our security controls.
1. Roles and Responsibilities
2. Roles and responsibilities related to our information security program and the protection of our customer’s data are well defined and documented.
3. Information Security Program
We have an information security program in place that is communicated throughout the organization. Our information security program follows the criteria set forth by SOC 2.
1. Continuous Monitoring
We continuously monitor our security and compliance status to ensure there are no lapses.
Section 4: Data privacy
At TipHaus, data privacy is a top priority—we strive to be trustworthy stewards of all sensitive data.
1. Privacy Shield
TipHaus maintains an active Privacy Shield Membership
2. Regulatory compliance
TipHaus evaluates updates to regulatory and emerging frameworks continuously to evolve our program.
3. Privacy Policy and DPA
TipHaus Commitment to Security