Difference between revisions of "Security"

From zFairs Contest Management
(Created page with "'''We take security of your data very seriously.''' All of our sites use the latest SSL to encrypt the content we send to you and to encrypt the content you send to us. Ou...")
 
 
(9 intermediate revisions by 2 users not shown)
Line 1: Line 1:
 +
== Security Overview ==
 +
 
'''We take security of your data very seriously.'''  
 
'''We take security of your data very seriously.'''  
  
Line 7: Line 9:
 
All access to our servers is logged and can only be accessed by a network admin with the proper credentials.
 
All access to our servers is logged and can only be accessed by a network admin with the proper credentials.
  
 +
'''Encryption -'''
 +
We utilize encryption at every level, data in transit and data at rest is encrypted. The only exception to this is uploaded files which are currently not encrypted at rest but are encrypted in transit, such as project/entry pictures. These files will be encrypted at rest in the future and are part of ongoing NIST compliance efforts.
  
 
'''Security -'''  
 
'''Security -'''  
Line 13: Line 17:
 
:'''Hardware:''' Our servers reside behind firewall and are actively backed up. There is no external remote access to our servers; to access our servers an authorized user must be on our internal network.  
 
:'''Hardware:''' Our servers reside behind firewall and are actively backed up. There is no external remote access to our servers; to access our servers an authorized user must be on our internal network.  
  
:'''Data:''' Your data is stored in our secure database which is only accessible from our internal network. Connections to our sites are encrypted with the latest SSL certificates.
+
:'''Data:''' Your data is stored in our secure database which is only accessible from our internal network. Connections to our sites are encrypted with the latest SSL certificates. Data stored in our database is encrypted.
  
 
:'''Software:''' Student information and personal information is only accessible by individuals with the proper authority; these users must be logged in to see this data. We do not share data with any third party entity. Every file that is uploaded to our system is immediately scanned to ensure the safety and integrity of our systems.
 
:'''Software:''' Student information and personal information is only accessible by individuals with the proper authority; these users must be logged in to see this data. We do not share data with any third party entity. Every file that is uploaded to our system is immediately scanned to ensure the safety and integrity of our systems.
  
 
:'''Location:''' All of our severs and your data are hosted in the USA, Utah and California. These locations are secure, managed locations with redundant systems such as power and internet.
 
:'''Location:''' All of our severs and your data are hosted in the USA, Utah and California. These locations are secure, managed locations with redundant systems such as power and internet.
 +
 +
'''Updates and Maintenance -'''
 +
We have regular scheduled maintenance on the 2nd Tuesday of each month; to help ensure we are up to date with the latest security updates and patches.
 +
 +
== Privacy Policy ==
 +
 +
We do comply with [https://www2.ed.gov/policy/gen/guid/fpco/ferpa/index.html FERPA] and [https://www.ftc.gov/enforcement/rules/rulemaking-regulatory-reform-proceedings/childrens-online-privacy-protection-rule COPPA].
 +
 +
In short we respect your data, it is not sold or shared with anyone. All data is stored in the USA including backups. You can request and see all of your data, and we will completely remove someone's data upon their request or the request of the data owner.
 +
 +
[https://www.zfairs.com/Legal/Privacy%20Policy.pdf Click here to see official privacy policy]
 +
 +
== Terms  & Conditions ==
 +
 +
[https://www.zfairs.com/Legal/Illuminating%20Software%20Terms%20of%20Use.pdf Click here to see the official terms and conditions]

Latest revision as of 20:01, 1 February 2022

Security Overview

We take security of your data very seriously.

All of our sites use the latest SSL to encrypt the content we send to you and to encrypt the content you send to us.

Our servers reside behind both physical and software firewalls.

All access to our servers is logged and can only be accessed by a network admin with the proper credentials.

Encryption - We utilize encryption at every level, data in transit and data at rest is encrypted. The only exception to this is uploaded files which are currently not encrypted at rest but are encrypted in transit, such as project/entry pictures. These files will be encrypted at rest in the future and are part of ongoing NIST compliance efforts.

Security - We have implemented and maintain several layers of security to ensure your data and our systems are secure and safe.

Hardware: Our servers reside behind firewall and are actively backed up. There is no external remote access to our servers; to access our servers an authorized user must be on our internal network.
Data: Your data is stored in our secure database which is only accessible from our internal network. Connections to our sites are encrypted with the latest SSL certificates. Data stored in our database is encrypted.
Software: Student information and personal information is only accessible by individuals with the proper authority; these users must be logged in to see this data. We do not share data with any third party entity. Every file that is uploaded to our system is immediately scanned to ensure the safety and integrity of our systems.
Location: All of our severs and your data are hosted in the USA, Utah and California. These locations are secure, managed locations with redundant systems such as power and internet.

Updates and Maintenance - We have regular scheduled maintenance on the 2nd Tuesday of each month; to help ensure we are up to date with the latest security updates and patches.

Privacy Policy

We do comply with FERPA and COPPA.

In short we respect your data, it is not sold or shared with anyone. All data is stored in the USA including backups. You can request and see all of your data, and we will completely remove someone's data upon their request or the request of the data owner.

Click here to see official privacy policy

Terms & Conditions

Click here to see the official terms and conditions