Back to home
ControlsBackupsIncident response

Security Exhibit

Administrative, technical, and organizational controls for enterprise security reviews.

Last updated: May 9, 2026

Governance and Access Control

  • Assign owners for application security, infrastructure operations, privacy, incident response, access administration, and release management.
  • Use tenant isolation, role-based access controls, strong authentication, optional MFA, least-privilege internal access, and periodic privileged access review.
  • Log administrative access and high-risk support or maintenance activity where technically available.

Data Protection

  • Use encryption in transit for supported deployments and document encryption-at-rest commitments by deployment model.
  • Separate production, test, and development environments where practical.
  • Protect exported reports, payroll data, student records, financial records, signatures, identity documents, backups, and logs according to sensitivity.

Monitoring, Change, and Vulnerability Management

  • Collect operational logs for authentication, security events, errors, performance, infrastructure health, and critical workflows where available.
  • Review code and controlled production releases, and evaluate vulnerabilities in application code, dependencies, containers, operating systems, and infrastructure.
  • Prioritize remediation based on severity, exploitability, affected systems, customer impact, and available mitigations.

Backups and Incident Response

Backup frequency, retention, restore testing, recovery time objective, and recovery point objective should be stated in the applicable agreement or operations runbook.

Security incidents should be triaged, contained, investigated, remediated, and communicated according to severity, the agreement, the DPA, and applicable law.

Security Exhibit — Hevra ERP