Integrity & Security
As a personal data processor, Parakey is obliged to take technical and organizational security measures to protect personal data and ensure the confidentiality, integrity and availability of Parakey's products and services.Β Β
This means that Parakey maintains the necessary security, such as encrypted storage and communication, authorization control, as well as the possibility to make registry extracts and delete personal data.Β
The actions taken by Parakey include, but are not limited to:
Authentication and encryption
All data communication is encrypted towards Parakey's services. To access the service, a personal login with username and password is required.
- Parakey uses encrypted communication in terms of Secure Sockets Layer (SSL) (SHA 256-bit, RSA 2048-bit). Parakey follows industry standards when it comes to encryption and has the same encryption as the one used when logging in to banks and government agencies.
β - The entire login procedure is encrypted, which means that no information is sent as unencrypted text. Passwords are never saved in plain text, but are stored in one-way encrypted format with a standard one-way cipher. This means that neither Parakey nor third parties can decrypt the user's password.
β - Parakey has procedures to help users detect unauthorized access to their account. By analyzing activity and informing users of events such as changing password or the first time the user logs in with a new mobile. The user can then easily choose to block their account and set a new password.
β - Parakey monitors and analyzes sign-in attempts to actively protect against brute-force attacks.
β - Continuous verification of the user takes place. This means that the logged on user's permissions are checked on all calls to Parakey's servers.
β - To reduce the risk of abuse, the number of signed-in sessions in Parakey's smartphone app is limited per user, when the same user signs in to a new device, the old session is automatically logged out. In Parakey's web portal (administrative interface), users can be logged in to several devices at the same time. The user can get a clear overview of all logged-in sessions on their profile page and manually log out the respective session.
Β - Access to the system is regulated based on role-based permissions, limiting users' access based on their role and place.
β
Storage and backups
Parakey's services are hosted by Amazon Web Services (AWS). Data storage and handling takes place geographically within Europe and the servers are located in data centers that are monitored 24/7.Β
- Only approved personnel have access to the data centers.
β - The data centers are fully equipped with fire protection and cooling and ventilation systems.
β - The data centers are equipped with a secondary power supply system to ensure power supply to the servers.
β - Parakey's services are built on a modern hosting platform with multilevel redundancy and scalability.
β - Backups are made automatically at predetermined intervals.
β - Parakey databases are encrypted to ensure high integrity of stored data.Β Β
β
Knowledge and information protection
All Parakey staff are bound by a non-disclosure agreement that prevents the disclosure of sensitive information and personal data.
β
Status of the service
Parakey works hard to ensure that our systems are available 24 hours a day, 7 days a week. On status.parakey.co you can follow the status of our applications and get information about planned maintenance.
β