Jump to content

Products
Learn More Get Started Contact Quantivo
Learn More
Get Started
Contact Quantivo

Quantivo is Serious About Analytics Data Security

Data security is our #1 priority

At Quantivo, we understand that your customer data is a vital business asset. We are committed to protecting the security and privacy of your data. Quantivo uses a multi-layered approach to securing your application data, whether it is in transit over networks, accessed within your application or stored in our data center facility.

Data center security

The Quantivo platform infrastructure is hosted in a data center facility meeting the highest standards for security availability, including:

  • Level 1 PCI Compliance
  • U.S. Commerce Department Safe Harbor certification
  • SAS 70 Type II compliance

Our hosting partner maintains stringent physical security measures, including biometric access controls and around-the-clock physical security. Other security measures include:

  • 24x7 monitoring
  • Advanced firewalls and network intrusion/prevention technologies
  • Firewall log analysis to spot unusual activity
  • Security patching, management backed by SAS-70 Type II audits

Application security

Quantivo applications run in a secure, multi-tenant environment in which each individual application resides in its own partition, unaffected by other tenants. In addition, we offer fine-grained, role-based access controls to the data. For example, you can give departments the ability to analyze only a specific subset of the data.

Quantivo logs all changes and access attempts to the service. These logs can be used to track who is accessing your data and for what purposes.

Customers access the data using a single, secure application developed by Quantivo. No generalized data access, third party tools or HTML access is allowed. Every request is authenticated to ensure that requests are not hijacked.

Encryption

Quantivo encrypts data in transit, in storage, and in the runtime environment:

  • Data in transit uses authenticated and encrypted SSL transfer mechanisms, both during uploads and when users access the service. Access can be configured to require 128-bit or 64-bit encryption.
  • Data is stored in an encrypted state that reflects our proprietary storage algorithms
  • Data in the runtime environment is disassembled into parts that are meaningless outside the Quantivo service.

Operating system security

Data from each tenant is partitioned and segregated at the file system level. There is no combination of multiple customer datasets in a single file and there is no 'uber' database containing all the tenants' data that could be subject to SQL injections, buffer overflows or other attacks.