SaleMove Certifications
Security

Security at the Core

SaleMove's security stack has
three distinct layers

SaleMove Security Stack

Infrastructure

Hardened Amazon Web Services (AWS) Infrastructure

SaleMove is exclusively hosted on AWS. SaleMove inherits the control environment AWS maintains and demonstrates via SSAE-16 SOC 1, 2 & 3, ISO 27001, FedRAMP/FISMA reports and additional certifications. In addition, SaleMove has deployed a 24/7 intrusion detection system that sits on-top of AWS with daily manual log reviews. All data is encrypted both in motion and at rest.

Application

SFDC practices with security at the core

SaleMove follows a Test-Driven Development (TDD) software development process including both multi-party manual and automated security checks based on OWASP application security principles. Application security controls include: defense in depth, positive security model, fail securely, run with least privilege, intrusion detection, amongst others. In addition, SaleMove undergoes third party penetration testing on a scheduled basis.

Personnel

Dedicated Security Personnel with SOC2-2 Audited Controls

SaleMove has dedicated GIAC GSEC certified security personnel who have responsibility for security across the SaleMove organization. All SaleMove employees undergo background checks along with initial and ongoing security training and testing. All access is two-factor authentication controlled, logged and run with least privilege controls.

Request our latest Architecture and Security White Paper,

SOC2-2 Audit, Third Party Network Vulnerability Audit,  Third Party Penetration Testing Audit or the SaleMove WISP

Architecture & Security

This White Paper details the SaleMove security framework and implementation