Parasail AI | Trust Center
Parasail Trust Center
Monitoring
Continuously monitored by Secureframe
Change Management
- Configuration and Asset Management Policy
- Baseline Configurations
- Secure Development Policy
Availability
- Backup Restoration Testing
- Uptime and Availability Monitoring
- Testing the Business Continuity and Disaster Recovery Plan
Organizational Management
- New Hire Screening
- Personnel Acknowledge Security Policies
- Advisor Meetings on Security
Confidentiality
- Data Classification Policy
- Data Retention and Disposal Policy
Vulnerability Management
- Vulnerability and Patch Management Policy
- Third-Party Penetration Test
Incident Response
- Lessons Learned
- Incident Response Plan Testing
- Tracking a Security Incident
Risk Assessment
- Vendor Due Diligence Review
- Risk Assessment
- Risk Register
Network Security
- Network Traffic Monitoring
- Automated Alerting for Security Events
- Network Security Policy
Access Security
- Unique Access IDs
- Encryption-in-Transit
- Encryption and Key Management Policy
Physical Security
- Physical Access Reviews
- Physical Access Restrictions
- Physical Security Policy
Monitoring
Change Management
Configuration and Asset Management Policy
A Configuration and Asset Management Policy governs configurations for new sensitive systems.
Baseline Configurations
Baseline configurations and codebases for production infrastructure, systems, and applications are securely managed.
Secure Development Policy
A Secure Development Policy defines the requirements for secure software and system development and maintenance.
Change Management Policy
A Change Management Policy governs the documenting, tracking, testing, and approving of system, network, security, and infrastructure changes.
Production Data Use is Restricted
Production data is not used in the development and testing environments, unless required for debugging customer issues.
Segregation of Environments
Development, staging, and production environments are segregated.
Availability
Backup Restoration Testing
Backed-up data is restored to a non-production environment at least annually to validate the integrity of backups.
Uptime and Availability Monitoring
System tools monitor for uptime and availability based on predetermined criteria.
Testing the Business Continuity and Disaster Recovery Plan
The Business Continuity and Disaster Recovery Plan is periodically tested via tabletop exercises or equivalents. Management makes changes based on test results.
Business Continuity and Disaster Recovery Policy
Governs required processes for restoring service or supporting infrastructure after a disaster or disruption.
Organizational Management
New Hire Screening
Hiring managers screen new hires or internal transfers to assess their qualifications, experience, and competency. New hires sign confidentiality agreements upon hire.
Personnel Acknowledge Security Policies
Internal personnel review and accept applicable information security policies at least annually.
Advisor Meetings on Security
Senior management and/or board of directors meets at least annually to review business goals, initiatives, and risks. The security team meets to discuss security risks, roles & responsibilities, and audit results.
Information Security Policy
Establishes the security requirements for maintaining the security, confidentiality, integrity, and availability of applications, systems, infrastructure, and data.
Disciplinary Action
Violations of security policies result in documented disciplinary action.
Internal Control Monitoring
A continuous monitoring solution for internal controls used in achieving service commitments.
Information Security Program Review
Management reviews the organization's security policies and procedures at least annually.
Security Awareness Training
Internal personnel complete annual training on information security obligations and responsibilities.
Acceptable Use Policy
Defines standards for appropriate and secure use of company hardware and systems.
Code of Conduct
Outlines ethical expectations and behavior standards.
Performance Reviews
Personnel are evaluated via a formal performance review at least annually.
Cybersecurity Insurance
Procured to minimize the financial impact of cybersecurity loss events.
Organizational Chart
Management maintains and publishes a formal organizational chart identifying positions of authority.
Performance Review Policy
Provides context and transparency into personnel performance and career development processes.
Internal Control Policy
Identifies how controls are maintained to safeguard assets and promote efficiency.
Independent Advisor
Includes independent senior management and external advisors overseeing cybersecurity.
Roles and Responsibilities
Outlines information security roles and responsibilities for personnel.
Confidentiality
Data Classification Policy
Details security and handling protocols for sensitive data.
Data Retention and Disposal Policy
Specifies how customer data is retained and disposed based on compliance requirements.
Vulnerability Management
Vulnerability and Patch Management Policy
Outlines processes for responding to identified vulnerabilities.
Third-Party Penetration Test
Annual penetration test by an external party; critical findings are tracked.
Incident Response
Lessons Learned
Management provides a "Lessons Learned" document post-security incidents.
Incident Response Plan Testing
Periodic testing of the Incident Response Plan; management may modify the plan based on results.
Tracking a Security Incident
Documenting and analyzing identified incidents according to the Incident Response Plan.
Incident Response Plan
Outlines processes for identifying, prioritizing, and resolving security incidents.
Risk Assessment
Vendor Due Diligence Review
Vendor SOC 2 reports are collected and reviewed annually.
Risk Assessment
Performed to identify relevant threats related to security, availability, confidentiality, and fraud.
Risk Register
Records risk mitigation strategies for identified risks and development of controls.
Vendor Risk Management Policy
Defines a framework for onboarding and managing vendor relationships.
Risk Assessment and Treatment Policy
Governs conducting risk assessments considering threats and vulnerabilities.
Vendor Risk Assessment
New vendors assessed prior to engagement; reassessment occurs annually.
Network Security
Network Traffic Monitoring
Security tools provide monitoring of network traffic to the production environment.
Automated Alerting for Security Events
Notifies teams of potential security events.
Network Security Policy
Identifies requirements for protecting information and systems across networks.
Access Security
Unique Access IDs
Personnel assigned unique IDs for accessing sensitive systems.
Encryption-in-Transit
Service data transmitted over the internet is encrypted.
Encryption and Key Management Policy
Supports the secure use of cryptographic controls.
Administrative Access is Restricted
Restricted based on least privilege principles.
Removal of Access
Access is removed upon termination or when no longer needed.
User Access Reviews
Scheduled reviews of user access to validate it according to job responsibilities.
Access Control and Termination Policy
Governs authentication and access to applicable systems.
Access to Product is Restricted
Non-console access to production infrastructure is restricted.
Physical Security
Physical Access Reviews
Periodic reviews of physical access based on job responsibilities.
Physical Access Restrictions
Processes for modifying physical access based on needs.
Physical Security Policy
Details physical security requirements for company facilities.
Visitor Control
All visitors to production facilities must formally sign in unless pre authorized.
Communications
Description of Services
Descriptions of the company's services are available to personnel and external users.
Communication of Security Commitments
Security expectations are communicated via the company's website.
Privacy Policy
Details the company's privacy commitments to users.
Communication of Critical Information
Critical information is communicated to external parties as needed.
Confidential Reporting Channel
Available for internal personnel and external parties to report security concerns.
Terms of Service
Published or shared with external users.