ServinYOU
  • Home
  • Pricing
  • FAQ

Security

How We Protect Your Data & Business

Quick Navigation

  • Security Overview
  • Infrastructure Security
  • Data Protection
  • Payment Security
  • Access Control
  • Monitoring & Response
  • Compliance & Certifications
  • Incident Response
  • Your Best Practices

1. Security Overview

At ServinYOU, security is not an afterthought—it's built into every layer of our platform. We understand that you're trusting us with sensitive business and customer data, and we take that responsibility seriously.

Our security approach follows industry best practices and standards:

PCI DSS Level 1 SOC 2 Type II GDPR Compliant SSL/TLS Encryption
🔒 Our Security Promise: We invest continuously in security infrastructure, conduct regular audits, and maintain incident response procedures to ensure your data is protected at the highest level.

2. Infrastructure Security

Cloud Infrastructure

We host our systems on Amazon Web Services (AWS), one of the world's most secure cloud providers. AWS provides:

  • Multi-region redundancy for disaster recovery
  • Advanced DDoS protection and intrusion detection
  • Automated backup and recovery systems
  • ISO 27001 and SOC 2 compliance

Network Security

Firewalls & WAF

We deploy Web Application Firewalls (WAF) and network firewalls to protect against unauthorized access and common web attacks.

DDoS Protection

Advanced protection against Distributed Denial of Service attacks ensures your kiosks remain online even during attacks.

24/7 Monitoring

Our security team monitors network traffic and systems 24/7/365 for suspicious activity and anomalies.

3. Data Protection

Encryption in Transit

All communication between your kiosks and our servers uses TLS 1.2 encryption (or higher). This ensures that data transmitted over the internet cannot be intercepted or modified.

  • Mandatory HTTPS/SSL for all connections
  • Strong cipher suites (256-bit encryption minimum)
  • Perfect Forward Secrecy (PFS) enabled
  • Certificate pinning on mobile apps

Encryption at Rest

All data stored on our servers is encrypted using industry-standard algorithms:

  • AES-256 encryption for sensitive data
  • Encrypted database backups
  • Encryption keys stored separately from encrypted data
  • Regular key rotation procedures

Data Isolation

Your business data is logically isolated from other customers. We use:

  • Separate database schemas per customer
  • Row-level security policies
  • Tenant isolation at the application layer

Backup & Disaster Recovery

  • Automated daily backups across multiple geographic regions
  • 99.99% availability guarantee with documented SLA
  • Tested disaster recovery procedures
  • Data retention policies aligned with regulatory requirements

4. Payment Security (PCI DSS)

✓ PCI DSS Level 1 Compliant
We comply with the Payment Card Industry Data Security Standard, the most stringent security requirement for businesses that handle payment cards.

Payment Processing

We never store full credit card numbers on our servers. Instead:

  • Payment data is transmitted directly to PCI-certified payment processors (Stripe, Square)
  • We only store tokenized references to payment methods
  • All payment processing is encrypted end-to-end
  • Tokens expire after a set period and are regularly rotated

PCI DSS Requirements We Meet

  • Secure Network: Firewalls, segmentation, no direct public access to cardholder data
  • Cardholder Data Protection: Encryption, secure deletion, access restrictions
  • Vulnerability Management: Regular patching, antivirus software, security updates
  • Access Control: User authentication, role-based permissions, audit trails
  • Monitoring & Testing: Intrusion detection, security testing, vulnerability scanning
  • Security Policy: Comprehensive written policy, employee training, incident procedures

3D Secure & Fraud Prevention

  • Support for EMV/chip card standards
  • 3D Secure (3DS) authentication where available
  • Real-time fraud detection and prevention
  • Velocity checking and anomaly detection

5. Access Control & Authentication

User Authentication

  • Strong Password Requirements: Minimum 12 characters, complexity requirements
  • Multi-Factor Authentication (MFA): Optional 2FA via authenticator apps or SMS
  • Session Management: Automatic logout after inactivity, secure session tokens
  • Device Recognition: Warning alerts for logins from new devices

Role-Based Access Control

Different users have different permission levels:

  • Admin: Full access to all features and settings
  • Manager: Access to operations, reports, and employee management
  • Staff: Limited access to operational functions only
  • Read-Only: Reporting and analytics access only

Audit Logging

  • All user actions are logged with timestamps
  • Sensitive changes require additional authentication
  • Audit logs retained for 7 years for compliance
  • Searchable audit trail available to admins

Employee Access

  • Only authorized employees can access customer data
  • Background checks for security-sensitive roles
  • Access logs for all production environments
  • Mandatory security training for all employees

6. Continuous Monitoring & Incident Response

Security Monitoring

  • Real-Time Alerts: Automated alerts for suspicious activity
  • Log Analysis: Machine learning models detect anomalies
  • Security Events: Failed login attempts, permission changes, data access patterns
  • Vulnerability Scanning: Daily automated scans for security vulnerabilities
  • Intrusion Detection: IDS/IPS systems monitor for attacks

Regular Security Testing

  • Penetration Testing: Annual third-party penetration tests
  • Vulnerability Assessments: Quarterly scans by security firms
  • Code Reviews: Security-focused code review before every release
  • Dependency Scanning: Automated checks for vulnerable third-party libraries

Incident Response Plan

We maintain a comprehensive incident response plan:

  • Detection: Automated alerts within seconds
  • Containment: Immediate action to prevent further damage
  • Investigation: Root cause analysis within 24 hours
  • Notification: Affected customers notified within 72 hours (as required by law)
  • Recovery: Systems restored from clean backups
  • Documentation: Detailed post-incident reports generated

7. Compliance & Certifications

Industry Standards

PCI DSS Level 1

Payment Card Industry Data Security Standard - The highest level for businesses processing payment cards.

SOC 2 Type II

Service Organization Control audited for security, availability, and integrity of our systems.

GDPR Compliant

Full compliance with European General Data Protection Regulation requirements.

CCPA/CPRA Ready

California Consumer Privacy Act compliance for California residents' data rights.

Infrastructure Certifications

  • AWS ISO 27001 (Information Security Management)
  • AWS SOC 2 (Security, Availability, Processing Integrity)
  • AWS PCI DSS Level 1 (Payment Card Standards)

8. Reporting Security Issues

If you discover a security vulnerability or believe there has been a security incident, please report it immediately:

Email: security@servinyou.com
Response Time: We will acknowledge your report within 24 hours
Confidentiality: All security reports are kept confidential

Responsible Disclosure

We ask that security researchers:

  • Report vulnerabilities privately before public disclosure
  • Do not access or modify data beyond what's necessary to demonstrate the vulnerability
  • Do not launch attacks against our systems
  • Allow us 90 days to fix verified vulnerabilities before public disclosure

Security Breach Notification

In the unlikely event of a data breach, we will:

  • Notify all affected customers within 72 hours
  • Provide clear information about what data was exposed
  • Offer free credit monitoring or identity protection services
  • Work with law enforcement and regulators as needed

9. Your Security Best Practices

While we secure our systems, you also play an important role in security:

Account Security

  • Use a strong, unique password (12+ characters)
  • Enable Multi-Factor Authentication (MFA)
  • Don't share login credentials with anyone
  • Log out when finished, especially on shared computers
  • Update your password every 90 days

Kiosk Security

  • Keep kiosks physically secure in your location
  • Use secure Wi-Fi networks with strong passwords
  • Keep kiosk software up-to-date with latest patches
  • Monitor kiosk activity through the dashboard
  • Report unusual activity immediately

Data Protection

  • Never share customer data with unauthorized parties
  • Use HTTPS and never send sensitive data over plain HTTP
  • Regularly back up critical business information
  • Educate staff about phishing and social engineering

Payment Security

  • Never store full credit card numbers
  • Only process payments through our secure system
  • Don't store card data in emails or documents
  • Comply with PCI DSS requirements in your operations
Last Updated: September 2024
This Security page reflects our current security practices and commitments.
← Back to Home