Trust Center - sonatype
Security You Can Trust
Trust is foundational to the success of our business. Trust = Transparency + Accountability. We strive for transparency through clear communication across functions and levels. We hold ourselves accountable for the promise we make to our employees, investors, and customers.
To earn your trust, we share our security and compliance programs with you. We continuously evolve with the ever-changing world around us to safely manage the confidentiality, integrity, and availability of not only Sonatype's but also the customers' data and services that we manage.
Controls
Infrastructure security
| Control | Status |
|---|---|
| Remote access encrypted enforced The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection. |
Organizational security
| Control | Status |
|---|---|
| Code of Conduct acknowledged by employees and enforced The company requires employees to acknowledge a code of conduct at the time of hire. Employees who violate the code of conduct are subject to disciplinary actions in accordance with a disciplinary policy. |
Product security
| Control | Status |
|---|---|
| Control self-assessments conducted The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA. |
|
| Vulnerability and system monitoring procedures established The company's formal policies outline the requirements for the following functions related to IT / Engineering: - vulnerability management; - system monitoring. |
|
| Penetration testing performed The company's penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs. |
Internal security procedures
| Control | Status |
|---|---|
| Continuity and Disaster Recovery plans established The company has Business Continuity and Disaster Recovery Plans in place that outline communication plans in order to maintain information security continuity in the event of the unavailability of key personnel. |
|
| Development lifecycle established The company has a formal systems development life cycle (SDLC) methodology in place that governs the development, acquisition, implementation, changes (including emergency changes), and maintenance of information systems and related technology requirements. |
|
| Management roles and responsibilities defined The company management has established defined roles and responsibilities to oversee the design and implementation of information security controls. |
|
| Organization structure documented The company maintains an organizational chart that describes the organizational structure and reporting lines. |
|
| Roles and responsibilities specified Roles and responsibilities for the design, development, implementation, operation, maintenance, and monitoring of information security controls are formally assigned in job descriptions and/or the Roles and Responsibilities policy. |
|
| Security policies established and reviewed The company's information security policies and procedures are documented and reviewed at least annually. |
|
| System changes communicated The company communicates system changes to authorized internal users. |
|
| Access requests required The company ensures that user access to in-scope system components is based on job role and function or requires a documented access request form and manager approval prior to access being provisioned. |
|
| Incident response policies established The company has security and privacy incident response policies and procedures that are documented and communicated to authorized users. |
|
| Company commitments externally communicated The company's security commitments are communicated to customers in Master Service Agreements (MSA) or Terms of Service (TOS). |
Data and privacy
| Control | Status |
|---|---|
| Data retention procedures established The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data. |
|
| Data classification policy established The company has a data classification policy in place to help ensure that confidential data is properly secured and restricted to authorized personnel. |