Tracker Data Security
Preventing unauthorized access to your sensitive data is Tracker's paramount concern. That's why we employ the latest security mechanisms, data encryption, access protocols and system redundancies.
- One database per customer means a physical wall isolates your private data, with Tracker’s Software as a Service (SaaS) option
- On-premises option available and easily implemented behind your organization’s firewall utilizing software and security protocols that match your IT policies
- 256 bit digital encryption at multiple layers protects your data privacy at rest, in transit and at every stage, including secure VPN transfer of encrypted nightly backups between data centers
- SAS 70 Type II, Trust Guard® and PCI Data Security® certified and Sarbanes-Oxley/HIPAA compliant data center prevents identity theft and ensures privacy
- Complex password and authorization protocols are strictly enforced using five layers of user account security: authenticated logon, enforced password complexity, six defined user roles, granular data access rules, configurable security levels
- 100% uptime is guaranteed, with East and West coast operations, secure nightly backups, load balanced web servers and edge-to-edge system redundancy for disaster recovery
- Carrier-class threat management, undergoing 30,000-point system scans daily to immediately flag security hazards
- Servers free from spyware, viruses or cookiesand require no third-party installs, downloads or plug-ins, further managing back-door vulnerabilities
- DHS, SSA and E-Verify tested and approved , having passed all trials for secure communications with government servers, vetted and certified by the U.S. Department of Energy
- Maximized customer protection through locking out of ports that contain authentication information to eliminate hacking attempts which prevents insecure traffic such as FTP, Telnet, SSH, SFTP, POP 3, IMAP, Windows File shares, Database SQL connections and remote desktop terminal services
- Perfect track record of security Neither Tracker Corp nor its data center has ever experienced a security breach with any of its products.
The safety of a separate database
Using single-tenant architecture, Tracker's hosted solutions allocate a dedicated database to each customer, completely eliminating the risk of one organization logging on and accidentally seeing the data of another. This offers the highest level of data isolation and security possible. Unlike other hosted software providers, we never co-mingle data from multiple customers in a shared database.
State-of-the-industry encryption
Tracker Corp maximizes the security of all its communication done over the Internet, using certified 256-bit, Class 3 SSL encryption with RSA key length of 1024 bits, the highest level of web browser security. Tracker uses the transparent data encryption (TDE) feature of Microsoft® SQL Server 2008. Any data that is written into the database file is encrypted at rest. Snapshots and backups are also encrypted on disk. Because Tracker products are built upon industry-standard Microsoft technology, using proven web and database authentication guidelines, your organization is always protected, no matter how you deploy the software.
SAS 70 Type II certificated compliance
Tracker Corp’s data center has achieved third-party validation of its physical and IT security protocols under the Statement on Auditing Standards No. 70 (SAS 70) Type II, a standard that is internationally recognized as a mark of service quality, proven over an extended period of time. The complete contents of its confidential SAS 70 Type 2 Audit test results for all Data Communications (Matrix 7) controls state “ No relevant exceptions noted.”.
Uncompromising password protection and security protocols
All user accounts require complex passwords—and customer passwords are not known to Tracker Corp employees. Passwords are stored as encrypted in the database and your organization can specify additional password complexity requirements and inactivity timeout.24/7 monitored and guarded data center
Our data center is staffed 24/7/365 by certified systems administrators and network engineers. They continuously monitor network traffic and performance, power, temperature, intrusion vulnerabilities and other critical parameters. Physical access to the data center is strictly controlled by armed guards and video monitoring, all day and all night, all year.