OpenGraph Security Portal
Overview
OpenGraph was built by a team of security professionals with decades of experience providing security and software development services to startups, fortune 100 organizations, the United States federal government, and the Department of Defense.
Solution Security
Data Encrypted in Transit
All applications utilized for conducting OpenGraph business utilize the HTTP TLS 1.2 transport.
Customer Data Removal
Customer data is removed within 30 days of being no longer needed for OpenGraph to conduct their services.
Single Sign On
All OpenGraph employees are issued accounts using our Identity Provider which enforces MFA (multi-factor authentication) and the OpenGraph Password Policy.
Data Encrypted at Rest
Customer data is stored utilizing a well known cloud data storage platform which encrypts data at rest.
Privacy
Personally Identifiable Information (PII)
OpenGraph does not store customer PII.
Protected Health Information (PHI)
OpenGraph does not store PHI
Risk Management
Risk Ownership
All risk is ultimately owned and accepted by OpenGraph Chief Executive Officer.
Approved Risk Management Program
Risk assessment and risk treatment are applied to the entire scope of OpenGraph's information security and privacy program, and to all assets which are used within
Access Control
Staff Scoped Data Access
Employees are given access to company systems and customer information on an as-needed basis.
Human Resources
Employee Agreements
All contractors and employees must agree to an employment agreement and non-disclosure agreement prior to employment.
Background Screening
All employees and contractors must undergo local and federal background checks prior to beginning work for OpenGraph.
Off-boarding Process
When an employee or contractor is terminated, access to accounts is removed prior to an exit interview with the head of Human Resources.
Roles and Responsibilities
Roles and responsibilities are well defined and documented within the HR management software which OpenGraph utilizes.
Asset and Data Management
Asset Management Policy
Assets are tracked via an industry standard asset management software which ensure local security configurations are correctly enabled as per OpenGraph policies.
Physical Security
Physical Security Controls
OpenGraph data is stored via a well-known corporate storage provider which employs strong physical security Controls. All employee laptops are configured with encrypted hard disks to prevent data spillage in the event of a device being lost or stolen.
Network Security
Intrusion Prevention
OpenGraph implements industry leading endpoint protection on all company devices.
