Security
StarTree has implemented features in the following areas to protect data.Authentication and Authorization
- Controlled access on all company assets, using the principle of least privilege
- Strong password requirements
- Dedicated customer instances with controlled access
Encryption
- AES disk encryption for data at rest
- SSL/TLS for data encryption in transit
- Support for encryption options in AWS S3, Google Cloud Storage (GCS), and Amazon Elastic Block Storage (EBS)
Networking
- Antivirus
- Anti-malware
- Endpoint detection and response (EDR) solutions
- Monitoring, including for file integrity
- Intrusion detection
- Firewalls
Audit Trails and Data Loss Prevention
- Logging
- Offsite backups
- Regular updates to operating system and application software
- Testing and peer review and approval prior to pushing changes to production
- Authentication via OIDC compatible Identity Providers
- Authorization via fine-grained Role Based Access Control (RBAC) policies
- Encryption in transit via TLS 1.2+
- Encryption at rest: All stored data (including logs and metadata) is encrypted using industry-standard AES-256 encryption.
Compliance
StarTree Cloud has achieved the following certifications:- SOC2 Type 2
- ISO 27001
- HIPAA readiness
