Home > Support Articles > IT Management > SaaS Security: How CiraSync Keeps Subscriber Data Safe and Secure
Share on share on Facebook share on Twitter share on Facebook share by email

One of the most frequently asked questions we receive is, “What are the technical aspects of CiraSync security, and what steps do you take to ensure the security of users information?” When a company decides to look externally for help with information management, they want to ensure the utmost care is taken.

As a SaaS company, CiraSync integrates tightly with Microsoft Azure, utilizing the Azure Consent FrameworkIf you are a subscriber, your data is kept within the Microsoft Cloud. With over 100 million active users on Office 365 and more cloud security certifications than any other company, Microsoft Azure’s security is arguably the best in the world.

How does Microsoft ensure your security?

Microsoft has made it a priority to ensure the highest levels of stability and security within their operations as companies rapidly transfer to the cloud. Their goal is to make data accessible to users anywhere, without security compromises.

A common issue is that older security solutions are not designed to protect data that runs in SaaS applications. Traditional methods like firewalls don’t give the in-depth accessibility and visibility to applications that are held off premise. These methods don’t offer protection and security for cloud applications since they only keep track of a small region of traffic and have limited access to many applications activities.

Azure’s infrastructure is designed as a secure foundation that can host millions of customers simultaneously, giving users control and customization via a wide array of configurable security options. Azure prevents unauthorized and unintentional transfer of information between deployments in a multi-tenant architecture, using virtual local area network isolation, access control lists, load balancers, and IP filters, along with traffic flow policies; network address translation separates internal network traffic from external traffic.

To put it simply, because CiraSync is hosted on Azure servers, their security is our security.

We understand however, how this doesn’t answer all questions, as there are other points of vulnerability that can arrive.

Here are some more frequently asked questions.

How does CiraSync handle and protect PII data?

CiraSync is hosted in Azure. Azure has more cloud security certifications than any other cloud provider in the world. Thus, the physical security of CiraSync servers are quite secure.

Only three VMs are accessible via Public IP addresses. All ports are locked down to inbound internet traffic with the exception of the dashboard which allows port 443. Inter-server communication is via LAN connections on private IP addresses.

Backups stay in the Azure cloud. Logs and any caching used for performance purposes are purged after 30 days.

What is the architectural data flow of the system?

No formal architecture docs are available for release. CiraSync interfaces with Azure AD using the Graph API. Access to Office 365 Exchange is via Exchange Web Services.

All customer data is passed on the Microsoft Azure network – not the internet.

The backend tenant subscriber information is stored in SQL server. Logging and caching data is stored in MongoDB. Billing information is stored in QuickBooks online. All credit card transactions are done through Authorize.Net and is PCI compliant.

For performance reasons, contact lists and calendars are cached in a local database running on each worker. All cached information is automatically purged after 30 days.

Note that data at rest is encrypted on the file system.

What are the sign-on access and authentication policies?

CiraSync does not store or request passwords. No code exists to store customer passwords.

All authentication is done via the Azure consent process. After the user grants consent to the Azure CiraSync application, all interaction with Tenant data is done using the token.

At any time, you can remove consent for CiraSync.

What policies are in place to thwart insider breaches?

RDP access to servers is limited to the CTO and three staff members who are all long time employees and heavily committed to the success of CiraSync.

Our cloud admin and billing application has a shortlist of staff members able to access the console. There is no ability to export customer contact or calendar data.

Do you have a written information on privacy policy?

Our latest Privacy Policy in full can be found here: /data-privacy-policy/

More Tales from Tech Support