Security FAQ
What type of data is transmitted, processed, generated, and/or stored by Getint?
Does Getint handle sensitive (personal, health, financial, etc.) data?
How is data encrypted at rest, and how are keys/secrets managed?
Who has access to Personally Identifiable Information (PII) or Protected Health Information (PHI) within Getint?
Is the code stored in source control, and are clear-text passwords present?
What is Getint's data backup strategy?
How does Getint ensure the sanitization of backup tapes, failed hard drives, and other storage media?
How is patching of the software/application implemented in Getint?
How does data get to the application/service, and can external users load it?
How does Getint ensure the integrity of data, including input validation and related techniques?
Are strong password rules applied, and is multifactor authentication used?
How is the authorization of users managed, and is role-based access used?
Are secure code development practices used to develop the product?
Who is responsible for the maintenance and update of the software?
Last updated
Was this helpful?
