Additional Security Information
This topic covers the additional security procedures that Uniphore adheres to in order to uphold a high level of security across the organization, including regular assessments, certifications, compliance, and general corporate security practices.
Secure Software Development Lifecycle
Uniphore integrates robust Secure Software Development Lifecycle (SSDLC) practices to identify and mitigate vulnerabilities throughout the software development process. Static Application Security Testing (SAST) is conducted with every code commit, ensuring early detection of security flaws in the codebase. This proactive approach seamlessly integrates into CI/CD pipelines, ensuring issues are addressed at their source before they progress further into the development lifecycle.
Uniphore complements the SAST and performs Dynamic Application Security Testing (DAST), evaluating the application in a runtime environment, identifying vulnerabilities that manifest during execution.
Security Assessments
Uniphore’s InfoSec team along with external third-party auditors regularly conducts Vulnerability Assessments (VA) and Penetration Testing (PT). In collaboration with Product Engineering, InfoSec performs quarterly internal and external VA, semiannual internal and external third-party VA/PT, and semiannual application-specific internal and external third-party VA/PT to ensure comprehensive security coverage.
Additionally, Manual Penetration Testing (MPT) is regularly performed to uncover complex security risks that our automated tools may overlook. Together with VA/PT, which combines automated scanning with manual verification, these practices deliver a comprehensive and robust layer of security assurance, ensuring that Uniphore's products meet the highest security standards.
Note
MPT/VA/PT reports contain vulnerabilities which are classified based on criticality and SecOps-specific requirements.
The following activities are performed as part of the Uniphore security assessments:
Internal and External Network VA/PT
Applications VA/PT
Automated security focused source code review
Comprehensive security focused source code review
Remediation Testing
Reporting
Remediation Follow Up
Certifications and Compliance Programs
We use best practices and industry standards to achieve compliance with industry-accepted general security and privacy frameworks, which in turn helps our customers meet their own compliance standards.
ISO/IEC 27001:2013
Uniphore is ISO/IEC 27001:2013 certified and will be periodically audited by an independent certification body to confirm that Uniphore continues to meet the requirements of this standard.
Payment Card Industry Data Security Standard (PCI DSS)
Uniphore is a Level 1 PCI DSS Service Provider that engages an Independent Qualified Security Auditor (QSA) to perform an annual assessment of Uniphore’s control environment covering all 12 PCI DSS requirements for the design, implementation, and continuous improvement of controls for safeguarding cardholder data and sensitive information.
Uniphore has received our annual Certificate of Compliance (CoC) and an associated Attestation of Compliance (AoC) for Level 1 PCI certification and will be periodically audited by a Qualified Security Assessor (QSA) to assess whether the organization conforms to the PCI DSS requirements.
SOC2
Uniphore is SOC2 TypeII certified, the American Institute of Certified Public Accountants (AICPA) Service Organization Controls (SOC) reports give assurance over control environments as they relate to the retrieval, storage, processing, and transfer of data. The reports cover IT General controls and controls around availability, confidentiality and security of customer data. The SOC 2 reports cover controls around security, availability, and confidentiality of customer data.
GDPR
Uniphore adheres to the strict data protection principles set out in the EU privacy law on General Data Protection Regulation (GDPR).
HIPAA
Uniphore adheres to the standards of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
Corporate Security
The following corporate security practices are implemented at Uniphore to uphold high security standards across all aspects of the business.
Annual Security Training and Assessments
All employees participate in annual Information Security Awareness and are assessed periodically.
Information Security Policies and Processes
Uniphore maintains a documented set of policies that regulate the use of information, including its receipt, transmission, processing, storage, controls, distribution, retrieval, access, and presentation. This includes the laws, regulations, and practices that regulate how Uniphore manages, protects, and disseminates confidential information. In addition, Information Security policies are published and communicated to all employees and all Employees acknowledge their responsibilities in protecting customer data as a condition of employment.
Risk Management
Uniphore performs Risk management through detailed methodology to identify information security risks, conduct risk assessment, risk evaluation and risk treatment of the identified risk.
Risk management process includes systematic application of management policies, procedures, and practices to the activities of communicating, consulting, establishing the context and identifying, analyzing, evaluating, treating, monitoring, and reviewing risk.
Endpoint security
Endpoint devices are secured with hard drive encryption, endpoint detection and remediation (EDR) and advanced malware detection with central management and control.
All devices are managed via a central, cloud based Mobile Device Management (MDM) system.