The ISA Solution does not accept or store any payment related information and thus services provided by Instasafe do not fall under the scope of PCI DSS compliance. Furthermore, Instasafe does not handle any client data and any information passing through the ISA servers are end to end encrypted and hence inaccessible even to Instasafe. The ISA Solution also employs a multi-tenant architecture which ensures traffic and data of every customer is logically isolated from the others.
Even though PCI DSS compliance is not a requirement for Instasafe, provisions/security standard as per PCI DSS are maintained.
- All data including backups are stored within a secure network with stringent access control rules
- All access to data requires multiple authentications to be passed
- All stored data and data passing through ISA servers is encrypted
- Instasafe follows a rigorous vulnerability management process comprising of automated as well as manual scanning with no compromise on security
- Vulnerability management process is ingrained in SDLC and any detected vulnerability is resolved as soon as it is flagged
- The entire infrastructure is constantly monitored