Unauthorized Data Access Prevention
As mentioned previously in Authentication and Authorization data access is strictly controlled for both Uniphore and Uniphore customer employees, using various systems such as Auth0 by Okta, Teleport, SSO and MFA, Role based authorization, Policies, and uses JWT tokens.
The above methods allow for multi-level security across Uniphore systems and applications, ensuring the following protections are in place:
Bot Detection
Suspicious IP Throttling
Brute Force Protection
Breached Password Detection
Granular Access Control
Session Recording
Real-time Auditing
Traceability and Accountability (for every operation)
Tenant Data Isolation
Uniphore also performs regular security assessments, adheres to various compliance and security certifications, and upholds a high standard of corporate security practices, for detailed information on security assessments, compliance and certifications, and corporate security see Additional Security Information.
Monitoring
In addition to the above data access protection systems and services, the following are monitored and reported against to track access and application usage:
User and access - The AD system acts as the master system. Any configuration changes here are audited.
Policy Management - All changes done by an administrator are logged in audit logs and are available as APIs as well.
Access Management - If a change is made on User Groups access to data OR functionality, it is also fully logged and audited and available as API or through the UI.
Anomaly Detection - Some alerts are driven by anomaly detection algorithms, which analyze metrics to identify unusual patterns or deviations from normal behavior.
GuardDuty - Account and workload threat detection.
CloudTrail - Monitoring and Intrusion Detection System (IDS).
Additional system monitoring is in place for various purposes. See Monitoring and Incident Response for more information.