A high-level security infrastructure ensures customer data is never compromised.
At iTools, we know that security is crucial - that's why security is our top priority. We devote significant resources to continually develop our world-class security infrastructure. The result: unsurpassed security and privacy for our customers' information.
Security measuresAmong other security measures, iTools provides:
- Experienced, professional engineers and security specialists dedicated to round-the-clock data and systems protection.
- Continuous deployment of proven, up-to-date security technologies.
- Ongoing evaluation of emerging security developments and threats.
- Complete redundancy throughout the entire iTools online infrastructure.
- Total commitment to a secure, scalable, private, collocated system (unlike a hosted system arrangement, iTools manages all aspects of its operations).
Physical Security
iTools' production equipment is collocated in Auckland at a facility that provides 24-hour physical security, redundant electrical generators, redundant data center air conditioners, and other backup equipment designed to keep servers continually up and running.
Data Encryption
ITools leverages the strongest encryption products to protect customer data and communications, including 128-bit Comodo SSL Certification and 1024-bit RSA public keys. The lock icon in the browser indicates that data is fully shielded from access while in transit.
User Authentication
Users access iTools only with a valid username and password combination, which is encrypted via SSL while in transmission. Users are prevented from choosing weak or obvious passwords. An encrypted session ID cookie is used to uniquely identify each user.
Application Security
iTools' robust application security model prevents one customer from accessing another's data. This security model is reapplied with every request and enforced for the entire duration of a user session.
Operating System Security
ITools enforces tight operating system-level security by using a minimal number of access points to all production servers. We protect all operating system accounts with strong passwords, and production servers do not share a master password database. All operating systems are maintained at each vendor's recommended patch levels for security and are hardened by disabling and/or removing any unnecessary users, protocols, and processes.
Database Security
Whenever possible, database access is controlled at the operating system and database connection level for additional security. Access to production databases is restricted to a limited number of points, and production databases do not share a master password database.
Server Management Security
All data entered into the iTools application by a customer is owned by that customer. ITools employees do not have direct access to the iTools production equipment, except where necessary for system management, maintenance, monitoring, and backups. ITools does not utilize any managed service providers. The iTools systems engineering team provides all system management, maintenance, monitoring, and backups.
Reliability and Backup
All networking components, SSL accelerators, load balancers, Web servers, and application servers are configured in a redundant configuration. All customer data is stored on a primary database server. All customer data is stored on carrier-class disk storage using RAID disks and multiple data paths. All customer data, up to the last committed transaction, is automatically backed up off site.
© Copyright 2005 iToolsOnline Limited. All rights reserved. Contact Us






