White Paper on Data Security & Privacy
Data Security & Data Privacy
MobileArq has implemented multiple strategies to protect its data and thus prevent a data breach. Multiple layers of security measures, designed and implemented by our certified security personnel, ensure that the data under the stewardship of MobileArq is protected and secure. The five separate areas under which the security measures are implemented include the following:
- Data Handling Practices and App Security
- Server and Network Security
- Security Expertise
- Software as a Service Agreement (SaaS)
- Parent Education
- The data is encrypted in transit and the data is not accessible except through a protected login.
- Careless password management is one of the most common ways to enter an account. For administrators, we do not provide all the three pieces of information in one place. The admin site is a completely different URL than the app.
- We enforce strong passwords for users too - minimum 8 characters, must include a special character, number and an upper case letter. After a certain number of login attempts, they are locked out.
- We exchange data with the district through a secure transfer or site. There is no sharing of data via email or other insecure means.
- Each school district requires its own code to signup and additionally, email serves as verification. Each user needs to set up their own password to enter their school's app.
- Testing of MobileArq server and application level security time and again by ethical hackers.
- Malware Protection
- Scanning and detection of all kinds of malware on all types of files on the server
- Smart detection and prevention of any methods of attack: back doors, web shells, viruses, hacker tools, ‘black hat SEO’ scripts, phishing pages, and many others
- Denial of Service protection.
- Real-time blacklists
- Advanced anti-evasion protection
- Threat Intelligence protection
- Malicious bot protection.
- Automatic removal of malicious code from websites
- Advanced protection rules for SQL injection, XSS, CSRF, RFI, LFI.
- Advanced protection for WordPress, Joomla, Drupal, Magento, and other popular web applications.
- Brute force protection (Detects and blocks web authentication brute force attacks, without relying on either status codes or logs).
- Anti-spam protection (Blocks web spam).
- All Virtual Patches for Zero Day vulnerabilities
- Data loss protection rules
- PCI-DSS compliance (Meets PCI-DSS WAF compliance requirements).
- Domain source blocking
- Web shell protection
- Whitelisting and blacklisting.
- Advanced false positive prevention
- Updates multiple times daily