C2FO Security - C2FO
C2FO Security
Last updated on April 16, 2024
Mission Statement
Our security team is dedicated to keeping your information secure while ensuring that we provide the best service possible. We do it with an unwavering philosophy of making security a requirement in everything we do. C2FO is always working to improve our security posture through better process and automation. In short, we make security convenient.
Verified Secure
Every year, we hire certified, independent third-party professionals to perform detailed audits of all our security practices.
SOC 2 Type 2
Our SOC 2 Type 2 report provides reasonable assurance that C2FO’s practices are achieved based on the AICPA Trust Services Criteria for security, availability, processing integrity and confidentiality. You can email the team at security@c2fo.com to request a copy of the most recent SOC 3 report for a summary of the results.
ISO/IEC/27001
C2FO is certified compliant with the International Organization for Standardization’s 27001 Information Security Management Standard. This widely recognized standard measures every aspect of C2FO’s organizational and technical controls against global security standards.
Penetration Testing
In addition to our own internal vulnerability assessments, we contract certified professionals to find and exploit vulnerabilities in our product at least once every year. Everything found is classified based on risk, duly prioritized and remediated accordingly.
Protecting Your Privacy
Your personal data is yours and we take great care to keep it that way. C2FO only stores and processes the data we need to provide the best service possible. Your data is always encrypted, at rest and in transit, using top industry standards. Above all, we value your Right to Privacy by giving you full control over your data. For more on how we secure PII, read our official Privacy Policy.
Secure By Design
We practice security in depth which means making security a requirement for everything we do.
Establishing a Baseline
We build our information security requirements on four key pillars:
- Applicable regulations;
- Contractual obligations;
- Compliance with standards like those mentioned above; and
- Best practices and industry standards.
Need to Know and Least Privilege
Need to Know and Least Privilege are universal concepts for any security program, not just C2FO. The goal is to limit access in a responsible and unintrusive way. Over the course of any 90-day period, access logs will start to reveal a pattern showing us exactly what behavior we can expect to see from anyone or anything that is functioning properly. That behavior is exactly what is needed and nothing more. We will work to prune away any access that isn’t reflected in the story told by those logs.
Risk-based
All security policies are based on risk. First, classify all information. Then, we consider the likelihood that the information could be compromised. Finally, we consider the impact on the business if a compromise did occur. With those three aspects ranked, we can create a risk score.
Role-based
Everyone has their role to play when it comes to security. This starts with their role within the company and continues to the team, the project and the assets with which they’re associated. We align these roles with access in a way that is consistent with our philosophy.
Developing securely
We make security a requirement throughout the development lifecycle. Our team of security engineers is involved with the engineering architecture, feature design, code review and continuous monitoring after release. All code is manually reviewed to ensure security, stability and completeness. There are automated scans throughout the development process that check code for common vulnerabilities found in the NVD listing.
Encryption
All data is encrypted at rest and in transit using industry standards.
Security in the Cloud
Our service is deployed to both AWS and GCP across multiple geographical regions giving you the option of where to house your data. Both cloud providers feature top-of-the-line security controls which we configure and closely monitor using cloud security posture management (CSPM) tools.
Providing a Secure Platform
Our security practices aren’t limited to our development and best practices. It’s important to us that we provide the security features you need too.
Data Integrity
We regularly make database backups and restoration tests to minimize data loss.
Always On Call
All services are integrated into central log monitoring, analysis and alerting tools so you know that someone is always ready to respond if there’s an incident.
ERP Integration
C2FO offers multiple light touch options to integrate with your ERP seamlessly. These non-invasive approaches leverage simple data-sharing methods, ensuring your ERP remains unchanged. Once configured, your ERP will send data to the C2FO platform following best-in-class industry security standards to support your own cashflow marketplace.
Always Improving
The security climate is always changing and so are the threats. It’s important to us that we keep up. That’s why we treat every security audit, every vulnerability assessment, and every security incident that makes news as opportunities to grow.