Security

For any organization, security is critical. That's why we take every precaution necessary to ensure only authorized users can gain access to your information on CoThrive. Rest assured, our standards are consistent with industry best practices, and we employ multilevel technology from leading security vendors with proven track records.

 

Application Level Protection.

CoThrive protects your data by ensuring that only authorized users can access it.

  • Administrators assign data security rules that determine which users have access to which data.
  • All data is encrypted in transfer and access is governed by strict password security policies (6 character minimum with at least 1 alpha, 1 numeric and 1 special character). All passwords are stored in MD-5 hash format.
  • Applications are monitored for security violation attempts.
  • Incremental data backups are performed every 6 hours. Complete backups are performed daily to both disk and tape, with tape providing a second level of physical protection.
  • CoThrive utilizes a high-performance multi-tenant SaaS system architecture that prevents one organization from seeing another organization's data, unless data is explicitly shared.
  • An audit trail of all system access and data updates is continuously maintained.

Facility Level Protection.

CoThrive’s security standards are consistent with industry best practices.

  • Datacenter originally built as NEBS-Compliant central office and upgraded to a data center.
  • Multiple carrier internet backbones using only premium tier-1 backbone providers.
  • Border gateway protocol (BGP4) routing.
  • Physically independent fiber entry points.
  • Authorized personnel must pass biometric scanning to reach CoThrive system cages.
  • Exterior entrances feature silent alarm systems that notify law enforcement in the event of suspicion or intrusion.
  • 24/7/365 staffed network operations center.
  • SAS-70 II and PCI level 1 certified.

Network Level Protection.

Multilevel security products from leading security vendors and proven security practices ensure network security.

  • To prevent malicious attacks through unmonitored ports, external firewalls allow only http and https traffic on ports 80 and 443, along with ICMP traffic.
  • Switches ensure that the network complies with the RFC 1918 standard, while address translation technologies further enhance network security.
  • IDS sensors protect all network segments.