We, at adam.ai, place security at the core of what we do and believe that it is essential to keeping our promise to our users. We have procedures, checks, and audits in place to systematically help guarantee everyone uses our service in a secure and safe manner.
adam.ai adheres to enterprise-grade security features and certificates.
Because adam.ai is fully compliant with SOC 2 certification, you can rest assured that your content and files are well-protected, which further enhances our commitment to data security.
All third-party integrations utilize the industry-standard oAuth 2.0 authentication, ensuring secure data syncing between systems.
As it's compliant with industry standards and regulations such as GDPR, adam.ai ensures the protection of both enterprise and customer data.
All application data, files, and database content are encrypted at rest. Uploaded files receive an additional layer of security with 256-bit AES encryption.
User passwords are safeguarded with Salt and hashed multiple times, providing robust protection against unauthorized access.
Along with cloud storage buckets, every datastore that contains client data is secured at rest. Row-level encryption is also used by sensitive collections and tables. Consequently, neither physical access to the database nor logical access to the database are sufficient to read the most sensitive data because the data is encrypted even before it reaches the database.
Every time data is transmitted to our services, adam.ai employs TLS 1.2 or a later version. To increase the security of our data while it is in transit, we additionally use features like HSTS (HTTP Strict Transport Security). Cloudflare manages the server TLS keys and certificates, and they are distributed using application load balancers.
Application secrets are securely encrypted and kept in key vault service, with only authorized users having access to these values. Also we leverage detailed audit logs that track who accessed which secrets and when for compliance purposes and for detecting any unusual or unauthorized activity.
All business devices have mobile device management software installed on them as well as anti-malware security. To enforce secure endpoint configuration, including password manager, disc encryption, screen lock configuration, and software upgrades, we employ MDM software.
adam.ai protects remote access to internal resources with sophisticated identity-aware-proxy technology, an access tool utilized by the development team for SSH, Kubernetes, databases, internal web applications, and Windows. We avoid phishing by relying on biometrics and machine identification, and its zero-trust design prevents attacker pivots
adam.ai approaches vendor security from a risk-based perspective. A vendor's inherent risk rating is influenced by the following factors:
Once the inherent risk rating has been determined, the security of the vendor is evaluated in order to determine a residual risk rating and an approval decision for the vendor.
Our whole production infrastructure is structured with redundancies in highly available configurations dispersed across various availability zones. To retrieve crucial data, an auto-backup policy is in place.
Terraform is used to keep infrastructure as code, with modifications happening through a procedure very similar to the application-level software development process. We employ distinct infrastructure for development, staging, and live environments, with no data sharing between them.
We do thorough monitoring of infrastructure and application performance, which helps us spot problems before many clients do. Automated alerts with on-call schedules are set up, with escalation to all other members of the DevOps team.
Our security team use security monitoring to detect and respond to application assaults, abnormalities, and suspicious activity.