> For the complete documentation index, see [llms.txt](https://incident-tracker.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://incident-tracker.gitbook.io/docs/support/security/data-security-and-privacy.md).

# Data Security & Privacy

At Incident Tracker, safeguarding your data is a top priority. From encrypted communications to backup strategies, every part of our infrastructure and operations is designed to protect your information. Below is a summary of the key ways we ensure security, continuity, and trust.

{% hint style="info" %}
**Healthcare & HIPAA Environments:** If your organization handles Protected Health Information (PHI), see our dedicated [PHI Security Overview](https://incident-tracker.gitbook.io/docs/support/security/phi-security-overview) for HIPAA compliance details, BAA information, and healthcare-specific safeguards.
{% endhint %}

***

## End-to-End Encryption

* **Data in Transit:** All traffic between users and the platform is encrypted using **TLS 1.2**, authenticated via **DigiCert** certificates.
* **Data at Rest:** All customer data is encrypted using **AES-256**, including:
  * Database files
  * Field-level encryption for sensitive values (e.g. passwords)
  * Backups and transient SQL data
* **Private Access:** Application URLs are unlisted and protected from public indexing.

***

## Hosting & Infrastructure

Incident Tracker is fully hosted on **Microsoft Azure**, leveraging:

* Azure Defender for Cloud (CNAPP security platform)
* Regional failover zones and geo-redundant storage
* Application-level firewalls and VPN-restricted internal access

***

## Backup & Disaster Recovery

We maintain aggressive backup and retention policies:

* **SQL Backups:** Every 8 hours, stored in geo-redundant storage
* **Virtual Server Backups:** Daily at 2:30 AM UTC
* **Retention Timeline:**
  * Daily: 7 days
  * Weekly: 5 weeks
  * Monthly: 12 months
  * Yearly: 7 years
* **Recovery Time Objective (RTO):** 8 hours
* **Recovery Point Objective (RPO):** 6 hours

***

## Application Security

* **Penetration Testing:** Conducted regularly; recommendations are implemented promptly.
* **Authentication Options:**
  * Native login
  * SSO (Single Sign-On)
  * Google login
* **Access Control:** Role-based permissions, redaction tools, and account-level visibility restrictions.
* **Audit Logging:** All actions are timestamped and logged with IP origin.

***

## Monitoring & SLAs

* **Uptime Guarantee:** 99.95% uptime, monitored 24/7\
  [View Status](https://stats.uptimerobot.com/k2r2wfkOGw)
* **Support Availability:**
  * Phone: 7:30 AM – 4 PM (Eastern Time)
  * Email: Off-hours
  * Initial response within one business day
* **Security Patch Notifications:** Communicated via in-app banner

***

## Breach Prevention & Response

* **Zero Data Breach Record:** No reported breaches in over two decades of service.
* **Breach Protocol:** Follows a detailed, cross-departmental Data Breach Response Policy
* **Cyber Insurance:** Active policy provides coverage and forensic response support
* **Regular Security Training:** Mandatory for all employees annually

***

## Data Ownership & Retention

* **You own your data.** Always.
* **Exports:** Available at any time via the application or upon request
* **End of Service:** Before clearing systems, data is securely delivered to customers
* **Data Destruction:** Available upon request with a signed verification letter

***

## Internal Security Practices

* **VPN & Firewall Enforcement**
* **2FA Authentication** for admin access
* **Access Logs** stored for 1 year and reviewed daily
* **Clean Desk, Remote Access, Server Security, and Risk Policies** followed
* **Dedicated Customer Databases:** No multi-tenant data mixing
* **Quarterly Security Reviews**

***

<details>

<summary>Security Responsibility Matrix</summary>

<table data-header-hidden data-full-width="true"><thead><tr><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Category</strong></td><td><strong>Responsibility</strong></td><td><strong>Incident Tracker</strong></td><td><strong>Client</strong></td></tr><tr><td><strong>Infrastructure Security</strong></td><td>Hosting platform and physical infrastructure</td><td>✅ (Microsoft Azure)</td><td>❌</td></tr><tr><td></td><td>Network security (firewalls, DDoS protection)</td><td>✅</td><td>❌</td></tr><tr><td></td><td>System uptime &#x26; performance monitoring</td><td>✅ (99.95% uptime excl. maintenance)</td><td>❌</td></tr><tr><td></td><td>Scheduled maintenance communication</td><td>✅ (In-app banners)</td><td>❌</td></tr><tr><td><strong>Application Security</strong></td><td>Application access controls</td><td>✅ (Admin tools and roles)</td><td>✅ (Set up and manage roles)</td></tr><tr><td></td><td>Single Sign-On (SSO) integration</td><td>✅ (Supports SSO setup)</td><td>✅ (Configure Entra ID or other IdP)</td></tr><tr><td></td><td>SCIM / Graph API user provisioning</td><td>✅ (API endpoints &#x26; documentation)</td><td>✅ (Set up assignments and mappings)</td></tr><tr><td></td><td>Security patches &#x26; updates</td><td>✅</td><td>❌</td></tr><tr><td><strong>Data Protection</strong></td><td>Encryption in transit (HTTPS/TLS)</td><td>✅</td><td>❌</td></tr><tr><td></td><td>Encryption at rest</td><td>✅ (via Azure)</td><td>❌</td></tr><tr><td></td><td>Data ownership</td><td>❌</td><td>✅</td></tr><tr><td></td><td>Data export capabilities</td><td>✅ (Export available)</td><td>✅ (Initiate request or self-serve)</td></tr><tr><td></td><td>Post-termination data handling</td><td>✅ (Final export &#x26; clearance)</td><td>✅ (Request and confirm export)</td></tr><tr><td></td><td>Data destruction verification</td><td>✅ (Letter available upon request)</td><td>✅ (Request if desired)</td></tr><tr><td><strong>Account &#x26; User Management</strong></td><td>User provisioning / deprovisioning</td><td>❌</td><td>✅</td></tr><tr><td></td><td>Password policies (if not using SSO)</td><td>✅</td><td>✅ (Train users)</td></tr><tr><td></td><td>User awareness and training</td><td>❌</td><td>✅</td></tr><tr><td><strong>Incident &#x26; Support Handling</strong></td><td>Incident detection and monitoring</td><td>✅</td><td>❌</td></tr><tr><td></td><td>Response &#x26; resolution</td><td>✅ (1 business day initial response)</td><td>✅ (Report issues promptly)</td></tr><tr><td></td><td>Data breach notification (if applicable)</td><td>✅</td><td>❌</td></tr><tr><td><strong>Compliance &#x26; Legal</strong></td><td>Hosting platform compliance (Azure)</td><td>✅</td><td>❌</td></tr><tr><td></td><td>Data privacy &#x26; regulation compliance</td><td>✅</td><td>✅ (As applicable to organization)</td></tr><tr><td></td><td>Legal jurisdiction</td><td>✅ (Westmoreland County, PA)</td><td>❌</td></tr><tr><td><strong>Business Continuity</strong></td><td>Backups and disaster recovery</td><td>✅</td><td>❌</td></tr><tr><td></td><td>Administrative access logging</td><td>✅</td><td>❌</td></tr><tr><td></td><td>Customer continuity planning</td><td>❌</td><td>✅</td></tr><tr><td><strong>Integrations &#x26; APIs</strong></td><td>API key/token security</td><td>✅ (Issued and validated)</td><td>✅ (Store securely)</td></tr><tr><td></td><td>Third-party system integrations</td><td>✅ (Supported via API)</td><td>✅ (Implement securely)</td></tr></tbody></table>

</details>
