Reflow Security Controls & Measures | By Sprinto

Founded in 2024

Reflow recognises that the confidentiality, integrity and availability of information and data created, maintained and hosted by us are vital to the success of the business and privacy of our partners.

As a service provider/product, we understand the importance in providing clear information about our security practices, tools, resources and responsibilities within Reflow so that our customers can feel confident in choosing us as a trusted provider.

This Security Posture highlights high-level details about our steps to identify and mitigate risks, implement best practices, and continuously develop ways to improve.

Controls (69)

Here are the controls implemented at Reflow to ensure compliance, as a part of our security program.

Product security (5)

  1. Production System User Review
    Entity's Infosec officer reviews and approves the list of people with access to production console annually

  2. Situational Awareness For Incidents
    Entity maintains a record of information security incidents, its investigation, and the response plan that was executed in accordance with the policy and procedure defined to report and manage incidents.

  3. Vulnerability Remediation Process
    Entity identifies vulnerabilities on the Company platform through the execution of regular vulnerability scans.

  4. Centralized Management of Flaw Remediation Processes
    Entity tracks all vulnerabilities and remediates them as per the policy and procedure defined to manage vulnerabilities.

  5. Notification of changes
    To help determine that only authorized changes are deployed, Entity's key personnel are notified when changes are deployed to the production environment

Data security (12)

  1. Termination of Employment
    Entity ensures logical access that is no longer required in the event of termination is made inaccessible in a timely manner.

  2. Production Databases Access Restriction
    Entity ensures that access to the production databases is restricted to only those individuals who require such access to perform their job functions.

  3. Multi-factor Authentication
    Entity requires that all staff members with access to any critical system be protected with a secure login mechanism such as Multifactor-authentication.

  4. User Privileges Reviews
    Entity's Senior Management or the Information Security Officer periodically reviews and ensures that access to the critical systems is restricted to only those individuals who require such access to perform their job functions.

  5. User Access Reviews
    Entity's Senior Management or the Information Security Officer periodically reviews and ensures that administrative access to the critical systems is restricted to only those individuals who require such access to perform their job functions.

  6. Encrypting Data At Rest
    Entity has set up cryptographic mechanisms to encrypt all production databases that store customer data at rest.

  7. Inventory of Infrastructure Assets
    Entity develops, documents, and maintains an inventory of organizational infrastructure systems, including all necessary information to achieve accountability.

  8. Data Backups
    Entity backs up relevant user and system data regularly to meet recovery time and recovery point objectives and verifies the integrity of these backups.

  9. Transfer of PII
    Entity ensures appropriate procedures are in place to ensure compliance with regulatory requirements related to transfer of personal data outside of the region from which it is collected.

  10. Inventory of Personal Data (PD)
    Entity maintains an inventory of categories of personal information collected along with its usage, sources and specific purposes for collection as per regulatory requirements ("Record of Processing Activities") and reviews it on an annual basis.

  11. Choice & Consent
    Entity ensures regulatory requirements regarding user consent are met prior to processing personal data.

  12. Data Subject Access
    Entity ensures that Subject Access Requests are being honored in accordance with the Privacy Policy.

Network security (6)

  1. Impact analysis
    Entity systems generate information that is reviewed and evaluated to determine impacts on the functioning of internal controls.

  2. Limit Network Connections
    Entity ensures that the production databases access and Secure Shell access to infrastructure entities are protected from public internet access.

  3. Transmission Confidentiality
    Entity has set up processes to utilize standard encryption methods, including HTTPS with the TLS algorithm, to keep transmitted data confidential.

  4. Anomalous Behavior
    Entity's infrastructure is configured to review and analyze audit events to detect anomalous or suspicious activity and threats.

  5. Capacity & Performance Management
    Entity has set up methods to continuously monitor critical assets to generate capacity alerts to ensure optimal performance, meet future capacity requirements, and protect against denial-of-service attacks.

  6. Data used in Testing
    Entity ensures that customer data used in non-Production environments requires the same level of protection as the production environment.

App security (5)

  1. Conspicuous Link To Privacy Notice
    Entity displays the most current information about its services on its website, which is accessible to its customers.

  2. Secure system modification
    Entity has procedures to govern changes to its operating environment.

  3. Approval of Changes
    Entity has established procedures for approval when implementing changes to the operating environment.

  4. Unauthorized Activities
    Entity uses Sprinto, a continuous monitoring system, to alert the security team to update the access levels of team members whose roles have changed.

  5. Login Sessions
    Entity ensures infrastructure cloud provider login sessions are terminated after a defined length of time.

Endpoint security (5)

  1. Malicious Code Protection (Anti-Malware)
    Where applicable, Entity ensures that endpoints with access to critical servers or data must be protected by malware-protection software.

  2. Full Device or Container-based Encryption
    Where applicable, Entity ensures that endpoints with access to critical servers or data must be encrypted to protect from unauthorized access.

  3. Endpoint Security Validation
    Entity has set up measures to perform security and privacy compliance checks on the software versions and patches of remote devices prior to the establishment of the internal connection.

  4. Session Lock
    Entity ensures that endpoints with access to critical servers or data are configured to auto-screen-lock after 15 minutes of inactivity.

  5. Endpoints Encryption
    Entity requires that all critical endpoints are encrypted to protect them from unauthorized access.

Corporate security (36)

  1. Code of Business Conduct
    Entity has a documented policy to define behavioral standards and acceptable business conduct.

  2. Organizational Structure
    Entity maintains an organizational structure to define authorities, facilitate information flow and establish responsibilities.

  3. Competency Screening
    Entity has procedures to ensure that all security-related positions are staffed by qualified individuals who have the necessary skill set.

  4. Personnel Screening
    Entity has established procedures to perform security risk screening of individuals before authorizing access.

  5. New Hire Policy Acknowledgement
    Entity has established procedures for new staff to acknowledge applicable company policies as a part of their onboarding.

  6. Security & Privacy Awareness
    Entity provides information security and privacy training to staff that is relevant to their job function.

  7. Performance Review
    Entity requires that all employees in client serving, IT, Engineering, and Information Security roles are periodically evaluated regarding their job responsibilities.

  8. Periodic Policy Acknowledgement
    Entity has established procedures for staff to acknowledge applicable company policies periodically.

  9. Automated Reporting
    Entity has provided information to employees, via various Information Security Policies/procedures, on how to report failures, incidents, concerns, or other complaints related to the services or systems provided by the entity in the event there are problems.

  10. Incident Reporting Assistance
    Entity has provided information to customers on how to report failures, incidents, concerns, or other complaints related to the services or systems provided by the Entity in the event there are problems.

  11. Risk Framing
    Entity performs a formal risk assessment exercise annually, as per documented guidelines and procedures, to identify threats that could impair systems' security commitments and requirements.

  12. Risk Assessment
    Each risk is assessed and given a risk score in relation to the likelihood of it occurring and the potential impact on the security, availability, and confidentiality of the Company platform. Risks are mapped to mitigating factors that address some or all of the risk.

  13. Fraud
    Entity considers the potential for fraud when assessing risks. This is an entry in the risk matrix.

  14. Third-Party Criticality Assessments
    Entity performs a formal vendor risk assessment exercise annually to identify vendors that are critical to the systems' security commitments and requirements.

  15. Assigned Cybersecurity & Privacy Responsibilities
    Entity's Senior Management assigns the role of Information Security Officer who is delegated to centrally manage, coordinate, develop, implement, and maintain an enterprise-wide cybersecurity and privacy program.

  16. Internal Audit using Sprinto
    Entity uses Sprinto, a continuous monitoring system, to track and report the health of the information security program to the Information Security Officer and other stakeholders.

  17. Periodic Review & Update of Cybersecurity & Privacy Program
    Entity's Senior Management reviews and approves the state of the Information Security program including policies, standards, and procedures, at planned intervals or if significant changes occur to ensure their continuing suitability, adequacy, and effectiveness.

  18. Management Review of Org Chart
    Entity's Senior Management reviews and approves the Organizational Chart for all employees annually.

  19. Management Review of Risks
    Entity's Senior Management reviews and approves the "Risk Assessment Report" annually.

  20. Management Review of Third-Party Risks
    Entity's Senior Management reviews and approves the "Vendor Risk Assessment Report" annually.

  21. Subservice organization evaluation
    Entity reviews and evaluates all subservice organizations periodically, to ensure commitments to Entity's customers can be met.

  22. Segregates Roles and Responsibilities
    Entity's Senior Management segregates responsibilities and duties across the organization to mitigate risks to the services provided to its customers.

  23. Subprocessor Requirements
    Entity ensures that appropriate remediation measures are in place when personal data is shared with vendors as a part of its processing activities.

  24. Data Protection Impact Assessment (DPIA)
    Entity conducts Data Protection Impact Assessments periodically in order to assess the regulatory risks associated with the processing of personal data.

  25. Data Protection Officer (DPO)
    Entity appoints a Data Protection Officer to assess and facilitate the entity's compliance with the provisions of the GDPR.

  26. EU Representative
    Entity appoints a EU Representative to serve as a point of contact between EU authorities, data subjects and the organization.

  27. Customer Obligations
    Entity maintains a list of all contractual obligations based on customer contracts.

  28. Retention of Policies
    Entity ensures that all policy documents are retained for at least (6) years from creation.

  29. Chief Privacy Officer (CPO)
    Entity appoints a Privacy Officer to assess and facilitate the entity's compliance with relevant regulatory requirements.

  30. Privacy Act Statements
    Entity includes Privacy Act statements on forms that collect information that will be maintained in a Privacy Act system of records, or provide Privacy Act statements on separate forms that can be retained by individuals.

  31. Asset Ownership Assignment
    Entity has set up mechanisms to assign and manage asset ownership responsibilities and establish a common understanding of asset protection requirements.

  32. Infosec training ack
    Entity requires that all staff members complete Information Security Awareness training annually.

  33. New Hire Security & Privacy Training Records
    Entity has established procedures for new staff to complete security and privacy literacy training as a part of their onboarding.

  34. Periodic Security & Privacy Training Records
    Entity documents, monitors, and retains individual training activities and records.

  35. Updates During Installations / Removals
    Entity periodically updates and reviews the inventory of systems as a part of installations, removals, and system updates.

  36. Inventory of Endpoint Assets
    Entity develops, documents, and maintains an inventory of organizational endpoint systems, including all necessary information to achieve accountability.