Data security & privacy

Learn more about how we safeguard our information 
assets, and those of our customers, against misuse, 
abuse or compromise.

Book a demo
learning platform hero image
これは div ブロック内のテキストです。
Our approach

Security and privacy our way

SCW'S Trust Centre is currently unavailable. For all enquiries/requests for security documentation, please contact security@securecodewarrior.com.

We apologise for any inconvenience.

illustration 1
Tools

How we secure our products

スケーラブルで魅力的

Cloud security & best practices

Our services are hosted on Amazon Web Services infrastructure and we use MongoDB Atlas for storage. We leverage their world-class data centers in the US and EU to protect information and meet core security and compliance requirements. More information about their security practices is available at: AWS Security & MongoDB Security

スケーラブルで魅力的

Training and awareness

As part of our initial onboarding process, as well as on an ongoing basis (at least annually), all staff receive training regarding their respective information security/privacy obligations. In addition. our engineers perform secure code training on the OWASP Top 10

スケーラブルで魅力的

Vulnerability management

We continuously monitor for malicious activity, and regularly scan our infrastructure, applications and third-party libraries for known vulnerabilities. All our products go through a series of peer reviews and security assessments prior to deployment, including third-party library scanning, static code analysis and static container analysis. We also regularly engage expert third-parties to perform penetration tests in addition to our internal testing and scanning programs.

スケーラブルで魅力的

Access and authentication

We support single sign-on (SSO) so you can implement your own authentication systems to control access to our platform. Within Secure Code Warrior, we implement least privilege principles and access to production data is restricted through security groups and limited to staff that strictly need it for support. We also use multi-factor authentication (MFA) and ephemeral credentials to strictly control access to production systems

Our security program

Your personal data is important to us and we are committed to protecting it through close adherence to international regulations and industry best practice.

セキュリティ証明書と文書

AICPA SOC 2 タイプ 2

お客様が Secure Code Warrior に、当社製品の使用から得た機密情報を預けていることは承知しています。そのために、弊社はお客様のデータの保護と機密保持を極めて重要視しています。すべてのお客様が Secure Code Warrior に信頼と自信を持てるように、常に最高の技術基準、組織的対策、業界で認められたベストプラクティスを追求しています。

当社の取り組みを示すために、Secure Code WarriorはSOC 2 Type IIレポートを無事に取得しました。これは、セキュリティ、可用性、機密性に関連するリスクを軽減するための適切な管理を実施していることを示しています。SOC 2 レポートは、Secure Code Warrior のような SaaS ベンダーの統制の有効性に関する保証を必要とするお客様のニーズを満たすように設計されています。このレポートは、認定を受けた独立した第三者企業による監査の結果です。 アメリカ公認会計士協会 (AICPA)

これらの監査は、ソフトウェアベンダーのデータセキュリティとプライバシーを評価するための業界全体の標準です。当社のタイプII監査は最も堅牢なタイプで、お客様のデータを保護するために当社が長期間にわたって統制を実施し、信頼性が高く一貫した保護手段を講じていることを証明することを目的としています。当社のSOC 2レポートにご興味がおありでしたら、担当のアカウントマネージャーにお問い合わせいただくか、当社のサポートチームにメールでお問い合わせください。 support@securecodewarrior.com

ISO 27001:2013/ISO 27701:2019

Secure Code Warriorは、当社のSOC 2 Type IIレポートに加えて、セキュリティとプライバシー体制をさらに強化するために、ISO 27001およびISO 27701規格の認証も受けています。

以下のリンクをクリックして、当社のISO認証を表示および検証してください。

評価アンケート

セキュアコードウォリアーのセキュリティパックには、以下のリソースが含まれています。
以下のリソースが必要な場合は、アカウントマネージャーに連絡するか、サポートチームにメールでお問い合わせください- support@securecodewarrior.com

-クラウドセキュリティアライアンス CAIQ

ホワイトペーパー

セキュリティとプライバシーに関するホワイトペーパーを読んで、情報資産を保護するためにポリシー、手順、AWS の世界クラスのセキュリティ機能をどのように活用しているかについて詳しく学んでください。

ホワイトペーパー

脆弱性を報告する

Secure Code Warrior Learning Platformのセキュリティ研究者またはユーザーで、潜在的なセキュリティ脆弱性を発見した場合は、責任ある方法でその情報を開示するようご協力いただければ幸いです。また、すぐにお知らせいただくことをお勧めします。

責任ある情報開示ポリシー

Our privacy team

Your personal data is important to us and we are committed to protecting it through close adherence to international regulations and industry best practice.

プライバシーポリシー

お客様のプライバシーは当社にとって重要であり、当社がお客様に関する情報を収集、使用、共有する方法について透明性を保つことも重要です。

当社が個人データを処理する方法と理由の詳細については、当社のプライバシーポリシーを参照してください。これは、当社のウェブサイトにアクセスしたり、当社のプラットフォームを使用したり、その他の方法で当社や当社のサービスと関わったりするすべての人に適用されます。

プライバシーポリシー

クッキー

までも、ウオツコと新品同様、めちゃくちゃめし、めちゃくちゃ。○クッキー(ビーグマツクロ)アインとコーン、通勤クッキーキキキキー。

クッキー

GDPR およびそれ以降

私たちは、取り扱う個人情報を保護することの重要性を認識し、世界中で適用される関連するデータ保護規制を顧客が満たすよう努めています。そのためには、EU GDPR の要件と業界のベストプラクティスを順守しています。

詳細については、以下のリンクをクリックしてください。

GDPR およびそれ以降

データ処理に関する補遺

当社のデータ保護補遺は、当社のサービスに合わせて作成され、お客様の国際契約上のニーズを満たすように設計されています。

これには、EUと英国のGDPR要件(国際移転に関する標準契約条項を含む)とCCPAの追加規定が組み込まれています。

データ処理に関する補遺

サブプロセッサー

当社は、サービスの提供を支援するために、当社に代わって個人データを処理する厳選された第三者と協力しています。

現在のサブプロセッサーのリストについては、以下のリンクをクリックしてください。

サブプロセッサーのリスト

国際送金

個人データをEEA/英国外に移転する場合、移転影響評価を実施し、その前に適切な保護措置が講じられていることを確認します。

詳細については、国際送金に関するページをご覧ください。

国際送金

Our legal team

Our dedicated Legal team helps our business meet the needs of our customers by providing strategic advice on an increasingly complex, global and ever-changing regulatory landscape.

利用規約

以下のリンクをクリックして、Secure Code WarriorウェブサイトとAPIの利用規約にアクセスしてください。

ウェブサイト利用規約

SCW API 利用規約

その他の文書

以下のリンクをクリックして、Secure Code Warriorとの関係に適切と思われるその他の法的文書にアクセスしてください。

セキュア・コード・ウォリアー・センセイ・ライセンス利用規約

SCWデブリンピック利用規約への参入

商標

W9 納税者の身分証明書