Our SaaS (Hosted) clients entrust us to manage their solutions and see us as an extension of their own IT teams. We take this responsibility very seriously, and begin by strictly following the rule of least privileged, that is, an employee will have access to data only if that data is needed for the employee to complete their job. What this means in practice is that very few people have access to the core of our IT stack.
We strive for 99.999% availability, and performing frequent data backups are a key component of being able to recover quickly from any event that causes service interruptions. To accomplish this we use a multi-layer backup strategy consisting of both directory level backups and full system backups. We apply reverse differential backups of all client data every 24 hours, with 90 days redundancy, and store two copies, one on-site at the datacenter on a separate storage device, and one at a secure off-site location. Additionally, we maintain full VM image backups which include the operating system and all instances available on hot-standby, so in the event of a server failure, the redundant server comes online.
User access to applications is controlled by enforcing uniform minimum standards to password management, authentication, and granular permissions based user roles. All access and user actions in the applications are logged, allowing us to perform a wide variety of analyses to detect unusual activity.
Our team continuously evaluate emerging security threats and proactively implement countermeasures designed to prevent unauthorized access or unplanned downtime of our services.