1. Security Overview
At ServinYOU, security is not an afterthought—it's built into every layer of our platform. We understand that you're trusting us with sensitive business and customer data, and we take that responsibility seriously.
Our security approach follows industry best practices and standards:
PCI DSS Level 1
SOC 2 Type II
GDPR Compliant
SSL/TLS Encryption
🔒 Our Security Promise: We invest continuously in security infrastructure, conduct regular audits, and maintain incident response procedures to ensure your data is protected at the highest level.
2. Infrastructure Security
Cloud Infrastructure
We host our systems on Amazon Web Services (AWS), one of the world's most secure cloud providers. AWS provides:
- Multi-region redundancy for disaster recovery
- Advanced DDoS protection and intrusion detection
- Automated backup and recovery systems
- ISO 27001 and SOC 2 compliance
Network Security
Firewalls & WAF
We deploy Web Application Firewalls (WAF) and network firewalls to protect against unauthorized access and common web attacks.
DDoS Protection
Advanced protection against Distributed Denial of Service attacks ensures your kiosks remain online even during attacks.
24/7 Monitoring
Our security team monitors network traffic and systems 24/7/365 for suspicious activity and anomalies.
3. Data Protection
Encryption in Transit
All communication between your kiosks and our servers uses TLS 1.2 encryption (or higher). This ensures that data transmitted over the internet cannot be intercepted or modified.
- Mandatory HTTPS/SSL for all connections
- Strong cipher suites (256-bit encryption minimum)
- Perfect Forward Secrecy (PFS) enabled
- Certificate pinning on mobile apps
Encryption at Rest
All data stored on our servers is encrypted using industry-standard algorithms:
- AES-256 encryption for sensitive data
- Encrypted database backups
- Encryption keys stored separately from encrypted data
- Regular key rotation procedures
Data Isolation
Your business data is logically isolated from other customers. We use:
- Separate database schemas per customer
- Row-level security policies
- Tenant isolation at the application layer
Backup & Disaster Recovery
- Automated daily backups across multiple geographic regions
- 99.99% availability guarantee with documented SLA
- Tested disaster recovery procedures
- Data retention policies aligned with regulatory requirements
4. Payment Security (PCI DSS)
✓ PCI DSS Level 1 Compliant
We comply with the Payment Card Industry Data Security Standard, the most stringent security requirement for businesses that handle payment cards.
Payment Processing
We never store full credit card numbers on our servers. Instead:
- Payment data is transmitted directly to PCI-certified payment processors (Stripe, Square)
- We only store tokenized references to payment methods
- All payment processing is encrypted end-to-end
- Tokens expire after a set period and are regularly rotated
PCI DSS Requirements We Meet
- Secure Network: Firewalls, segmentation, no direct public access to cardholder data
- Cardholder Data Protection: Encryption, secure deletion, access restrictions
- Vulnerability Management: Regular patching, antivirus software, security updates
- Access Control: User authentication, role-based permissions, audit trails
- Monitoring & Testing: Intrusion detection, security testing, vulnerability scanning
- Security Policy: Comprehensive written policy, employee training, incident procedures
3D Secure & Fraud Prevention
- Support for EMV/chip card standards
- 3D Secure (3DS) authentication where available
- Real-time fraud detection and prevention
- Velocity checking and anomaly detection
5. Access Control & Authentication
User Authentication
- Strong Password Requirements: Minimum 12 characters, complexity requirements
- Multi-Factor Authentication (MFA): Optional 2FA via authenticator apps or SMS
- Session Management: Automatic logout after inactivity, secure session tokens
- Device Recognition: Warning alerts for logins from new devices
Role-Based Access Control
Different users have different permission levels:
- Admin: Full access to all features and settings
- Manager: Access to operations, reports, and employee management
- Staff: Limited access to operational functions only
- Read-Only: Reporting and analytics access only
Audit Logging
- All user actions are logged with timestamps
- Sensitive changes require additional authentication
- Audit logs retained for 7 years for compliance
- Searchable audit trail available to admins
Employee Access
- Only authorized employees can access customer data
- Background checks for security-sensitive roles
- Access logs for all production environments
- Mandatory security training for all employees
6. Continuous Monitoring & Incident Response
Security Monitoring
- Real-Time Alerts: Automated alerts for suspicious activity
- Log Analysis: Machine learning models detect anomalies
- Security Events: Failed login attempts, permission changes, data access patterns
- Vulnerability Scanning: Daily automated scans for security vulnerabilities
- Intrusion Detection: IDS/IPS systems monitor for attacks
Regular Security Testing
- Penetration Testing: Annual third-party penetration tests
- Vulnerability Assessments: Quarterly scans by security firms
- Code Reviews: Security-focused code review before every release
- Dependency Scanning: Automated checks for vulnerable third-party libraries
Incident Response Plan
We maintain a comprehensive incident response plan:
- Detection: Automated alerts within seconds
- Containment: Immediate action to prevent further damage
- Investigation: Root cause analysis within 24 hours
- Notification: Affected customers notified within 72 hours (as required by law)
- Recovery: Systems restored from clean backups
- Documentation: Detailed post-incident reports generated
7. Compliance & Certifications
Industry Standards
PCI DSS Level 1
Payment Card Industry Data Security Standard - The highest level for businesses processing payment cards.
SOC 2 Type II
Service Organization Control audited for security, availability, and integrity of our systems.
GDPR Compliant
Full compliance with European General Data Protection Regulation requirements.
CCPA/CPRA Ready
California Consumer Privacy Act compliance for California residents' data rights.
Infrastructure Certifications
- AWS ISO 27001 (Information Security Management)
- AWS SOC 2 (Security, Availability, Processing Integrity)
- AWS PCI DSS Level 1 (Payment Card Standards)
8. Reporting Security Issues
If you discover a security vulnerability or believe there has been a security incident, please report it immediately:
Email: security@servinyou.com
Response Time: We will acknowledge your report within 24 hours
Confidentiality: All security reports are kept confidential
Responsible Disclosure
We ask that security researchers:
- Report vulnerabilities privately before public disclosure
- Do not access or modify data beyond what's necessary to demonstrate the vulnerability
- Do not launch attacks against our systems
- Allow us 90 days to fix verified vulnerabilities before public disclosure
Security Breach Notification
In the unlikely event of a data breach, we will:
- Notify all affected customers within 72 hours
- Provide clear information about what data was exposed
- Offer free credit monitoring or identity protection services
- Work with law enforcement and regulators as needed
9. Your Security Best Practices
While we secure our systems, you also play an important role in security:
Account Security
- Use a strong, unique password (12+ characters)
- Enable Multi-Factor Authentication (MFA)
- Don't share login credentials with anyone
- Log out when finished, especially on shared computers
- Update your password every 90 days
Kiosk Security
- Keep kiosks physically secure in your location
- Use secure Wi-Fi networks with strong passwords
- Keep kiosk software up-to-date with latest patches
- Monitor kiosk activity through the dashboard
- Report unusual activity immediately
Data Protection
- Never share customer data with unauthorized parties
- Use HTTPS and never send sensitive data over plain HTTP
- Regularly back up critical business information
- Educate staff about phishing and social engineering
Payment Security
- Never store full credit card numbers
- Only process payments through our secure system
- Don't store card data in emails or documents
- Comply with PCI DSS requirements in your operations
Last Updated: September 2024
This Security page reflects our current security practices and commitments.