OpenGraph Security Portal

Overview
OpenGraph was built by a team of security professionals with decades of experience providing security and software development services to startups, fortune 100 organizations, the United States federal government, and the Department of Defense.
Solution Security

Data Encrypted in Transit

All applications utilized for conducting OpenGraph business utilize the HTTP TLS 1.2 transport.

Customer Data Removal

Customer data is removed within 30 days of being no longer needed for OpenGraph to conduct their services.

Single Sign On

All OpenGraph employees are issued accounts using our Identity Provider which enforces MFA (multi-factor authentication) and the OpenGraph Password Policy.

Data Encrypted at Rest

Customer data is stored utilizing a well known cloud data storage platform which encrypts data at rest.
Privacy

Personally Identifiable Information (PII)

OpenGraph does not store customer PII.

Protected Health Information (PHI)

OpenGraph does not store PHI
Risk Management

Risk Ownership

All risk is ultimately owned and accepted by OpenGraph Chief Executive Officer.

Approved Risk Management Program

Risk assessment and risk treatment are applied to the entire scope of OpenGraph's information security and privacy program, and to all assets which are used within
Access Control

Staff Scoped Data Access

Employees are given access to company systems and customer information on an as-needed basis.
Human Resources

Employee Agreements

All contractors and employees must agree to an employment agreement and non-disclosure agreement prior to employment.

Background Screening

All employees and contractors must undergo local and federal background checks prior to beginning work for OpenGraph.

Off-boarding Process

When an employee or contractor is terminated, access to accounts is removed prior to an exit interview with the head of Human Resources.

Roles and Responsibilities

Roles and responsibilities are well defined and documented within the HR management software which OpenGraph utilizes.
Asset and Data Management

Asset Management Policy

Assets are tracked via an industry standard asset management software which ensure local security configurations are correctly enabled as per OpenGraph policies.
Physical Security

Physical Security Controls

OpenGraph data is stored via a well-known corporate storage provider which employs strong physical security Controls. All employee laptops are configured with encrypted hard disks to prevent data spillage in the event of a device being lost or stolen.
Network Security

Intrusion Prevention

OpenGraph implements industry leading endpoint protection on all company devices.

Powered By