Objective of shared security model
Privacera, our customers, and our partners have a joint responsibility to ensure the confidentiality, integrity, and availability of critical data. As part of our commitment to this goal, and due to the varying and flexible deployment models that Privacera offers, we have developed this shared security model to highlight the obligations of various stakeholders.
The following are the responsibilities of Privacera.
Access, Authentication, and Authorization
Use threat models to inform secure product design
Mandate code reviews prior to merging
Execute regular static and software composition analysis
Uphold Apache Ranger heritage
Conduct frequent penetration testing
Maintain coordinated vulnerability disclosure (CVD) program to facilitate receipt of information regarding security issues
Governance and security teams
Develop Data Access Governance strategy and information security policies
Ensure compliance with relevant legislation and regulations (e.g. GDPR, CCPA, HIPAA) Information technology and development teams
Identify, maintain, protect, and securely connect to Privacera all datasources with sensitive information
Follow externally-developed code policy when using functionality built on top of Privacera products
Provision, manage, de-provision, and secure user accounts maintained within supported Identity Providers (IdPs)
Enforce industry-standard authentication practices such as MFA
Account Administrators and Data Owners
Implement Privacera features such as discovery scans, tagging rules, and compliance workflows in accordance with governance program
Develop access control and encryption policies
Privacera (SaaS) or Customer (Self-hosted) Responsibility
The following are the responsibilities of Privacera (SaaS) or customer (Self-hosted):
Adhere to relevant compliance frameworks (e.g. PrivaceraCloud offers SOC 2 Type II attestion)
Stay up to date with latest versions of Privacera and third-party software
Configure software securely, including ensuring the use of industry-standard data-in-motion encryption
IaaS Provider Responsibility
Using a shared responsibility model, secure and ensure the availability of cloud hosting infrastructure: