YouTestMe Cybersecurity Policies

Business continuity and disaster recovery

Business continuity and disaster recovery cover planning and preparing for potential disasters or disruptions to ensure that the organization can continue to operate and recover in the event of an incident. YouTestMe Business Continuity Planning covers:
  1. Disaster Recovery Procedure
  2. Backup Strategy
  3. Restore Strategy

Backup and disaster recovery details

YouTestMe performs full daily backups, with the backup frequency and timing configurable according to client requirements. Backup data is stored redundantly in multiple locations, including Microsoft Azure Blob Storage and an independent off-site SFTP backup server. The standard production configuration retains backups for at least 30 days, unless different contractual or client-specific requirements apply. For disaster recovery, YouTestMe maintains a hot-standby PostgreSQL database that is continuously replicated from the primary database and can be used for rapid recovery if the primary database becomes unavailable. Backup restoration, service recovery, infrastructure disruption response, and operational continuity are governed by documented Business Continuity and Disaster Recovery procedures. Backup restoration and recovery procedures are tested periodically to verify that data and services can be successfully recovered.

Information security

Information security focuses on protecting information from unauthorized access, use, disclosure, disruption, modification, or destruction.
  1. YouTestMe Data Processing Agreement contains information on:
    1. Data privacy
    2. Confidentiality
    3. Disclosure of information
    4. Data security
    5. Import and export of data
    6. Access to and extraction of data
    7. Data ownerships
    8. Data protection
    9. Data destruction
    10. Security incidents
    11. Data breach response
  2. YouTestMe Security Policies contains information on:
    1. General security policies
    2. Production security policies
    3. Development policies
    4. Encryption in transit

End-to-end encryption

End-to-end encryption ensures both data in transit and at rest remain secure throughout the process:
  1. For encryption at rest, YouTestMe uses Microsoft Azure Disk Storage Server-Side Encryption (256-bit AES).
  2. For encryption in transmission (in transit), YouTestMe warrants that all client’s data will be encrypted using Transport Layer Security (TLS) 1.2 at an encryption level equivalent to or stronger than 256-bit AES encryption.

Deployment appliance hardening

Deployment appliance hardening covers security measures protecting YouTestMe virtual machines from security threats that can exploit vulnerabilities.

Cloud security

Cloud security focuses on securing cloud-based systems and data from unauthorized access, data breaches, and other security threats. In addition to all internal security measures, YouTestMe ensures cloud security by using top-notch cloud computing services compliant with the industry standards for cloud security like SOC 1, 2, 3, and ISO/IEC 27001:
  1. OVH Cloud compliance and certification
Previous A Step-by-Step Guide to Streamlined Online Registration, Payment, Training, and Testing Processes
Next How Data Is Stored in YouTestMe

Was this article helpful?