Security
An overview of Hyperspell’s security features and practices.
Governance
Hyperspell establishes policies and controls, monitors compliance with those controls, and proves the security and compliance to third-party auditors.
Our policies are based on the following foundational principles:
Least Privilege
Consistency
Defense in Depth
Continuous Improvement
Data Protection
Data at rest
All datastores are encrypted at rest. Sensitive collections and tables also use row-level encryption.
Data in transit
Hyperspell uses TLS 1.3 or higher everywhere data is transmitted over potentially insecure networks.
Data backup
Hyperspell backs-up all production data using a point-in-time approach. Backups are persisted for 30 days, and are globally replicated for resiliency against regional disasters.
Operational Security
Security education
Hyperspell provides comprehensive security training to all employees upon onboarding and annually. Hyperspell’s conducts threat briefings with employees to inform them of important security and safety-related updates that require special attention or action.
Identity and access management
Hyperspell employees are granted access to applications based on their role, and automatically deprovisioned upon termination of their employment. Further access must be approved according to the policies set for each application.
Multi-factor authentication is required for all employees to access company applications.
Responsible Disclosure
To report a vulnerability, please contact us for a Responsible Disclosure.