Parasail AI | Trust Center

Parasail Trust Center

Monitoring

Continuously monitored by Secureframe

Change Management

Availability

Organizational Management

Confidentiality

Vulnerability Management

Incident Response

Risk Assessment

Network Security

Access Security

Physical Security

Monitoring

Change Management

Configuration and Asset Management Policy
A Configuration and Asset Management Policy governs configurations for new sensitive systems.

Baseline Configurations
Baseline configurations and codebases for production infrastructure, systems, and applications are securely managed.

Secure Development Policy
A Secure Development Policy defines the requirements for secure software and system development and maintenance.

Change Management Policy
A Change Management Policy governs the documenting, tracking, testing, and approving of system, network, security, and infrastructure changes.

Production Data Use is Restricted
Production data is not used in the development and testing environments, unless required for debugging customer issues.

Segregation of Environments
Development, staging, and production environments are segregated.

Availability

Backup Restoration Testing
Backed-up data is restored to a non-production environment at least annually to validate the integrity of backups.

Uptime and Availability Monitoring
System tools monitor for uptime and availability based on predetermined criteria.

Testing the Business Continuity and Disaster Recovery Plan
The Business Continuity and Disaster Recovery Plan is periodically tested via tabletop exercises or equivalents. Management makes changes based on test results.

Business Continuity and Disaster Recovery Policy
Governs required processes for restoring service or supporting infrastructure after a disaster or disruption.

Organizational Management

New Hire Screening
Hiring managers screen new hires or internal transfers to assess their qualifications, experience, and competency. New hires sign confidentiality agreements upon hire.

Personnel Acknowledge Security Policies
Internal personnel review and accept applicable information security policies at least annually.

Advisor Meetings on Security
Senior management and/or board of directors meets at least annually to review business goals, initiatives, and risks. The security team meets to discuss security risks, roles & responsibilities, and audit results.

Information Security Policy
Establishes the security requirements for maintaining the security, confidentiality, integrity, and availability of applications, systems, infrastructure, and data.

Disciplinary Action
Violations of security policies result in documented disciplinary action.

Internal Control Monitoring
A continuous monitoring solution for internal controls used in achieving service commitments.

Information Security Program Review
Management reviews the organization's security policies and procedures at least annually.

Security Awareness Training
Internal personnel complete annual training on information security obligations and responsibilities.

Acceptable Use Policy
Defines standards for appropriate and secure use of company hardware and systems.

Code of Conduct
Outlines ethical expectations and behavior standards.

Performance Reviews
Personnel are evaluated via a formal performance review at least annually.

Cybersecurity Insurance
Procured to minimize the financial impact of cybersecurity loss events.

Organizational Chart
Management maintains and publishes a formal organizational chart identifying positions of authority.

Performance Review Policy
Provides context and transparency into personnel performance and career development processes.

Internal Control Policy
Identifies how controls are maintained to safeguard assets and promote efficiency.

Independent Advisor
Includes independent senior management and external advisors overseeing cybersecurity.

Roles and Responsibilities
Outlines information security roles and responsibilities for personnel.

Confidentiality

Data Classification Policy
Details security and handling protocols for sensitive data.

Data Retention and Disposal Policy
Specifies how customer data is retained and disposed based on compliance requirements.

Vulnerability Management

Vulnerability and Patch Management Policy
Outlines processes for responding to identified vulnerabilities.

Third-Party Penetration Test
Annual penetration test by an external party; critical findings are tracked.

Incident Response

Lessons Learned
Management provides a "Lessons Learned" document post-security incidents.

Incident Response Plan Testing
Periodic testing of the Incident Response Plan; management may modify the plan based on results.

Tracking a Security Incident
Documenting and analyzing identified incidents according to the Incident Response Plan.

Incident Response Plan
Outlines processes for identifying, prioritizing, and resolving security incidents.

Risk Assessment

Vendor Due Diligence Review
Vendor SOC 2 reports are collected and reviewed annually.

Risk Assessment
Performed to identify relevant threats related to security, availability, confidentiality, and fraud.

Risk Register
Records risk mitigation strategies for identified risks and development of controls.

Vendor Risk Management Policy
Defines a framework for onboarding and managing vendor relationships.

Risk Assessment and Treatment Policy
Governs conducting risk assessments considering threats and vulnerabilities.

Vendor Risk Assessment
New vendors assessed prior to engagement; reassessment occurs annually.

Network Security

Network Traffic Monitoring
Security tools provide monitoring of network traffic to the production environment.

Automated Alerting for Security Events
Notifies teams of potential security events.

Network Security Policy
Identifies requirements for protecting information and systems across networks.

Access Security

Unique Access IDs
Personnel assigned unique IDs for accessing sensitive systems.

Encryption-in-Transit
Service data transmitted over the internet is encrypted.

Encryption and Key Management Policy
Supports the secure use of cryptographic controls.

Administrative Access is Restricted
Restricted based on least privilege principles.

Removal of Access
Access is removed upon termination or when no longer needed.

User Access Reviews
Scheduled reviews of user access to validate it according to job responsibilities.

Access Control and Termination Policy
Governs authentication and access to applicable systems.

Access to Product is Restricted
Non-console access to production infrastructure is restricted.

Physical Security

Physical Access Reviews
Periodic reviews of physical access based on job responsibilities.

Physical Access Restrictions
Processes for modifying physical access based on needs.

Physical Security Policy
Details physical security requirements for company facilities.

Visitor Control
All visitors to production facilities must formally sign in unless pre authorized.

Communications

Description of Services
Descriptions of the company's services are available to personnel and external users.

Communication of Security Commitments
Security expectations are communicated via the company's website.

Privacy Policy
Details the company's privacy commitments to users.

Communication of Critical Information
Critical information is communicated to external parties as needed.

Confidential Reporting Channel
Available for internal personnel and external parties to report security concerns.

Terms of Service
Published or shared with external users.