Security

Version 1.0Updated 7 December 2020

Security Statement - Technical and Organizational Measures

At Hopin, we are committed to protecting the confidentiality, integrity and availability of our information systems and our customers data. We are constantly improving our security controls and analyzing their effectiveness to give you confidence in our solution.

Here we provide an overview of some of the security controls in place to protect your data.

You can reach our security team at [email protected]

Cloud Security

Data Center Physical Security

Facilities

Hopin uses Amazon AWS for data center hosting. AWS data centers are certified as ISO 27001, PCI DSS Service Provider Level 1, and or SOC 1 and 2 compliant. Learn more about Compliance at AWS.

AWS employs robust controls to secure the availability and security of their systems. This includes measures such as backup power, fire detection and suppression equipment, secure device destruction amongst others. Learn more about Data Center Controls at AWS.

On-Site Security

AWS implements layered physical security controls to ensure on-site security including, vetted security guards, fencing, video monitoring, intrusion detection technology and more. Learn more about AWS Physical Security.

Network Security

In-house Security Team

Hopin has a dedicated and passionate security team across the globe to respond to security alerts and events.

Third-Party Penetration Tests

Third party penetration tests are conducted against the application and supporting infrastructure at least annually. Any findings as a result of tests are tracked to remediation. Reports are available on request with an appropriate NDA in place.

Threat Detection

Hopin leverages threat detection services within AWS to continuously monitor for malicious and unauthorised activity.

Vulnerability Scanning

We perform regular internal scans for vulnerability scanning of infrastructure. Where issues are identified these are tracked until remediation.

DDoS Mitigation

Hopin uses a number of DDoS protection strategies and tools layered to mitigate DDoS threats. We utilize Cloudflare’s sophisticated CDN with built in DDoS protection as well as native AWS tools and application specific mitigation techniques.

Access Control

Access is limited to least privilege model required for our staff to carry out their jobs. This is subject to frequency internal audit and technical enforcement and monitoring to ensure compliance. 2FA is required for all production systems.

Encryption

In Transit

Communication with Hopin is encrypted with TLS 1.2 or higher over public networks. We monitor community testing & research in this area and continue to adopt best practices in terms of Cipher adoption and TLS configuration.

At Rest

Hopin data is encrypted at rest with industry standard AES-256 encryption. By default we encrypt at the asset or object level.

Availability & Continuity

Uptime

Hopin is deployed on public cloud infrastructure. Services are deployed to multiple availability zones for availability and are configured to scale dynamically in response to measured and expected load. Simulated load tests and API response time tests are incorporated into our release and testing cycle.

Hopin maintains a publicaly available status page which includes details on system availability categorised into product areas, scheduled maintenance windows, service incident history and security incident details.

Disaster Recovery

In the event of a major region outage, Hopin has the ability to deploy our application to a new hosting region. Our Disaster Recovery plan ensures availability of services and ease of recovery in the event of such a disaster. This plan is regularly tested and reviewed for areas of improvement or automation.

DR deployment is managed by the same configuration management and release processes as our production environment ensuring that all security configurations and controls are applied appropriately.

Application Security

Quality Assurance

Hopin’s Quality Assurance team reviews and tests code base on a per pod basis. The security team has resources to investigate and recommend remediation of security vulnerabilities within code. Regular syncs, training and security resources are provided to the QA team.

Environment Segregation

Testing, staging and production environments are logically separated from one another. No customer data is used in any development or test environment.

Security Champions

Hopin runs a Security Champions program with involvement contributions from each of the development teams.

Personal Security

Security Awareness

Hopin delivers a robust Security Awareness Training program which is delivered within 30 days of new hires and annually for all employees. In addition, we roll out quarterly focused training to key departments including Secure Coding, Data Legislation and Compliance obligations.

Information Security Program

Hopin has a comprehensive set of information security policies covering a range of topics. These are disseminated to all employees and contractors and acknowledgement tracked on key policies such as Acceptable Use, Information Security Policy and our Employee Handbook.

Employee Background Checks

All Hopin employees undergo a background check prior to employment which covers 5 years criminal history where legal and 5 years employment verification.

Confidentiality Agreements

All employees are required to sign Non-Disclosure and Confidentiality agreements.

Access Controls

Access to systems and network devices is based upon a documented, approved request process. Logical access to platform servers and management systems requires two-factor authentication. A periodic verification is performed to determine that the owner of a user ID is still employed and assigned to the appropriate role. Access is further restricted by system permissions using a least privilege methodology and all permissions require documented business need. Exceptions identified during the verification process are remediated. Business need revalidation is performed on a quarterly basis to determine that access is commensurate with the users job function. Exceptions identified during the revalidation process are remediated. User access is revoked upon termination of employment or change of job role.

Data Privacy

GDPR

Hopin maintains compliance with the European Union’s General Data Protection Regulation (GDPR). We use the E.U Commission approved standard contractual clauses for data transfer form the EEA to the United States.

PCI-DSS

As a card not present merchant, Hopin outsources our cardholder functions to a PCI-DSS Level 1 service provider. A copy of our SAQ-A can be available on request.

Privacy Policy

Hopin’s privacy policy, which describes how we handle data input into Hopin, can be found at /privacy. For privacy questions or concerns, please contact [email protected].

Third Party Security

Vendor Management

Hopin understands the risks associated with improper vendor management. We evaluate and perform due diligence on all of our vendors prior to engagement to ensure their security is to a suitable standard. If they do not meet our requirements, we do not move forward with them. Selected vendors are then monitored and reassessed on an ongoing basis, taking into account relevant changes.

Third-Party Sub Processors

Hopin uses third-party sub processors to provide core infrastructure and services which support the application. Prior to engaging any third party, Hopin evaluates a vendor’s security as per our Vendor Management Policy.

Vendor Location Service Provided Vendor DPA
Amazon AWS EU (IE) Application Hosting and Data Storage https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf
Amazon AWS US (Ashburn, VA) Static / Image Asset Storage https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf
Heroku EU (IE) Application Hosting https://www.salesforce.com/content/dam/web/en_us/www/documents/legal/Agreements/data-processing-addendum.pdf
CloudFlare US Content Delivery and Traffic Filtering https://www.cloudflare.com/media/pdf/cloudflare-customer-dpa.pdf
Datadog EU Log Aggregation & Analysis https://www.datadoghq.com/legal/msa/
Stripe EU, US Payment Processing Available on Request
Chargebee EU, US Subscription Management https://www.chargebee.com/privacy/dpa/
Redis Labs EU (IE) Data Storage https://redislabs.com/wp-content/uploads/2019/09/data-processing-addendum.pdf
MUX US A/V Ingestion, Transcoding & Distribution https://mux.com/files/mux-dpa.pdf
Twilio US A/V Ingestion, Transcoding & Distribution, Email Messaging https://www.twilio.com/legal/data-protection-addendum
Vonage US A/V Ingestion, Transcoding & Distribution https://www.vonage.com/legal/privacy-policy/
Pusher US In-Event Messaging https://pusher.com/legal/terms-of-service
Segment.io US Analytics https://segment.com/legal/data-protection-addendum/
Intercom US Customer Support https://www.intercom.com/legal/privacy
Zendesk EU, US Customer Support https://www.zendesk.com/company/privacy-and-data-protection/
Salesforce EU Organizer Sales CRM https://www.salesforce.com/content/dam/web/en_us/www/documents/legal/Agreements/data-processing-addendum.pdf
Google IE Internal Collaboration & Storage https://workspace.google.com/terms/dpa_terms.html

Responsible Disclosure

If you discover a vulnerability in Hopin’s information systems you can report it to us at [email protected]. Reports should include full details and steps to reproduce.