Your security is very important to us! Here is a summary of what we do every day to protect your data and ensure that we apply best practices on our SaaS platform.
Backups / Disaster recovery
Backups
Customer data is at the heart of Madiasoft teams’ focus. To ensure its integrity and availability, Madiasoft operates an efficient, redundant backup system.
The backup infrastructures are not located in the same region (i.e., the same data center) as the production systems. This organization ensures an optimal level of availability and integrity while meeting our RTO and RPO requirements.
The backup frequency and retention period are as follows:
- Customer files stored by Kafinea: Daily backup, 100-day retention
- Kafinea customer database: Daily backup, 7-day retention
Disaster recovery
- RPO: Recovery Point Objective, or data recovery point
For Kafinea, it is 24 hours by default. - RTO: Recovery Time Objective, or service recovery time
As standard, Madiasoft does not define an RTO for Kafinea.
However, in the event of a major incident resulting in a prolonged service interruption for a given customer, Madiasoft undertakes to restore the Kafinea Service within 48 hours, based on the most appropriate backup.
Database security
- Customer data is stored in a dedicated database—no data is shared between customers.
- Data access control rules implement complete isolation between customer databases running on the same cluster; no access is possible from one database to another.
Password security
Each Kafinea user is authenticated with a unique username and a strong password. Adding a second authentication factor is strongly encouraged and will soon be mandatory.
User passwords are not stored in plain text in Madiasoft’s information system.
The default rule for our scopes is to use non-reversible encryption functions such as “hashing” with secure algorithms.
System security
A hardening policy to secure operating systems is in place. The aim is to reduce the possible attack surface by disabling or removing non-essential items (services, applications, features, etc.). This involves implementing specific security options and ensuring software updates.
Hardening operations on server operating systems cover:
- Updates
- Account policy
- User and network permissions
- Logging
- Malware protection
- Services, roles, and features
- User space
- Disk space
Banking information security
- We never store credit card information on our own systems.
- Your credit card information is always transmitted securely directly between you and our PCI-compliant payment acquirers.
Application design security
Madiasoft has implemented an approach aimed at integrating security throughout the life cycle of the applications it develops. This approach is inspired by OWASP recommendations.
Data encryption
Data transfer over public networks
Data is encrypted during transfers over public networks using secure protocols (HTTPS, TLS, SFTP, SSH, etc.).
Certificates
To ensure the highest level of security, the HTTPS certificates used by Kafinea come from recognized public certificate authorities. The management of these certificates is governed by procedures covering their life cycle.
Encryption
The rules regarding encryption key length are:
Asymmetric encryption: greater than or equal to 2048 bits
Symmetric encryption: greater than or equal to 256 bits
Madiasoft uses encryption software based on AES256 to create secure archives.
Security vulnerability management
Vulnerability scanner
Scans across the entire Internet perimeter of Madiasoft’s information system are launched regularly, using a vulnerability scanner managed by Madiasoft’s security team.
These scans make it possible to verify the correct configuration of hardware and software in order to detect the emergence of vulnerabilities.
The results are reviewed and are subject to specific action plans.
Report security vulnerabilities
If you need to report a security vulnerability, please share the details by writing to security@madiasoft.com. These reports are handled with high priority, and the issue will be assessed and resolved by the Kafinea security team, in collaboration with the reporter.