Security
Customer Security & Backup Policy
NZ & AU Clients
(does not apply to US clients)
Data Residence:
All live data is hosted on the Amazon Web Services (AWS) platform in the Australia East region.
Data is replicated between regions within Australia.
All client data is backed-up in real time, and replicated to our Wellington Network Operations
Centre (NOC). The Wellington NOC site provides for spatially distinct real time backups and
also houses encrypted copies of hourly account snapshots for the past 7 days, and then daily
full archives across the entire contracted subscription period. Offline encrypted backups are
kept in a secure safe at the Wellington NOC. This provides for backup data across 2 different
countries with both on and off line repositories.
Data Security:
Core Schedule has a policy of “Least privilege”. Access to customer data is only provided on a
“need to use” basis. Access to customer data via the application, or via direct database access
is only available over an encrypted connection. All user passwords are stored as salted hashed
data and thus cannot be recovered. Core Schedule enforces a password policy for all user
passwords to meet modern security standards. Application access requires all users utilize SSL
connections.
Core Schedule staff use industry standard 2FA to access any client data. All access is logged
and monitored. All repository data (both on and offline) is encrypted.