We Obsess Over Data Protection
Protecting our customers’ information is a core element of our business model. It is integrated into our culture through formalised policies, procedures and supporting controls. We architect our service delivery environment and support systems using secure cloud models under controlled jurisdiction. To ensure our architecture operates according to specification, we have implemented an Information Security Programme based on Spain’s National Security Framework (ENS) and ISO/IEC 27001 as our security frameworks.
How We Protect Your Data
To meet our commitment to security and privacy, BlackfishID has implemented the following:
We continuously review our security and privacy measures to ensure any customer data we collect and process is adequately protected.
Our third-party vendor contracts contain terms to ensure vendors processing customer data have adequate data protection and privacy controls.
We use our own Managed Detection and Response solution to detect and respond to threats within our environment, and our Vulnerability Management module to identify endpoint exposures and prioritise remediation.
Our organisation-wide Information Security Management programme takes a risk-based approach to implementing defence-in-depth controls.
Key security controls include:
- Maintenance of Information Security Policies
- Vendor security and privacy risk management processes
- Information classification, handling and retention processes
- Use of the BlackfishID platform in our own environments
- Limiting access to customer data based on least privilege principles
- Ongoing management of workers’ access to customer data
- Endpoint protection for BlackfishID managed devices
- Network security
- Change management processes
- Patch management for endpoints
- Secure software development lifecycle processes
- Business continuity and disaster recovery processes
- Information security incident response processes
Accreditations and Certifications
BlackfishID is currently in the final audit phase of CPSTIC certification with Spain's National Cryptologic Centre (CCN). ENS Alto and ISO/IEC 27001 certification processes are underway.