Ediphi Security FAQ
At Ediphi, protecting your data is our top priority. This FAQ provides clear answers about our security, compliance, privacy, access controls, reliability, and features like Single Sign-On (SSO). Whether you're evaluating Ediphi or conducting a security review, you'll find straightforward information on how we keep your information secure and accessible.
In this article
Security & Compliance
How does Ediphi approach security?
We follow industry best practices and frameworks like SOC 2, with principles including defense-in-depth, least-privilege access, data minimization, and strict tenant isolation. Production access is tightly controlled and monitored, and our security program includes regular audits, employee training, vulnerability scanning, and incident response planning. You can learn more by visiting our Trust Center.
Do you have SOC 2 or ISO 27001 certification?
We have earned our SOC 2 Type 1 certification. It can be provided upon request via our our Trust Center.
Do you have an information security policy?
Yes, the policy is reviewed quarterly by our leadership team. It can be provided upon request, subject to CTO approval.
How do you manage the security risks of your third-party vendors?
Third-party vendors are carefully evaluated before onboarding, particularly those with access to customer data or critical systems. We prioritize vendors meeting recognized security standards such as SOC 2 or ISO 27001.
Core infrastructure vendors like AWS and Vanta undergo continuous security monitoring. Contracts are reviewed for data handling obligations, access is restricted to only what's necessary, and vendor risk is periodically reassessed as part of our ongoing security program.
Data & Privacy
What hosting platform do you use?
Amazon Web Services (AWS).
Where is customer data stored?
All data is primarily hosted in AWS’s US-EAST-1 (North Virginia) region.
What is your disaster recovery strategy?
We have best-practice safe guards in place to protect your data in the event of a disaster. We store encrypted backups across availability zones in the US with point-in-time recovery (PITR).
Who owns customer data?
Customers retain full ownership of their data and may access it any time via a SQL query to our API.
What is your data retention policy?
Data is retained indefinitely unless deletion is requested. When requested, the database instance is deactivated for ~90 days before full termination.
What Personal Information (PII) do you collect?
Usernames, and typical ‘business card’ data such as emails, job titles and office locations. Customers may also store client contact information. We do not collect sensitive personal data.
Are customer environments isolated from one another?
Yes, each tenant has an isolated environment to ensure data privacy and security.
Is data encrypted in transit and at rest?
Yes. TLS is used for all data in transit. Data at rest is encrypted with AES-256.
How do you manage encryption keys?
We use AWS Secrets Manager and 1Password with best practice encryption methods.
How do you notify customers of a security breach?
We follow a formal Incident Response Plan. Affected customers are notified promptly with details, impact, and mitigation steps. Regulators are notified as applicable.
Data Accessibility
Do I have access to our company data?
Enterprise customers can access our Data website to browse all database tables and test queries via a built-in SQL editor. Queries are executed through a single API endpoint authenticated by an API key, and run on a live synced read replica which ensures large or frequent queries don't impact application performance.
Can I write data to Ediphi using an API?
A limited set of endpoints are provided for enterprise customers that can be used to sync your Ediphi data with external sources such as CRM for opportunities, subcontractor contacts from bid solicitation software such as BuildingConnected, and employees and their positions. Projects can also be created via API, for instance, from a CRM system.
Do you have support for our data engineers?
Talk to us about your team needs and we will be happy to help!
Identity & Access Management
Do you support SSO and enterprise identity providers?
Yes, we support any OpenID Connect (OIDC) compliant provider including but not limited to Azure AD, Okta, and OneLogin. We recommend OIDC over SAML for better compatibility with web apps, though SAML is available on request.
Do you support MFA and password policies?
Yes. Multi-factor authentication, password complexity rules, and brute-force protection are available and configurable using SSO.
What levels of access do employees have to customer data?
Role-based access is enforced. Engineers may have temporary access for support, which is logged and permissioned via IAM roles.
For more information, see our official Ediphi Trust Center.