HirePOS Data Management and Security
This document outlines the comprehensive security measures and data protection practices implemented by Innercircle Technology Pty Ltd (HirePOS) to safeguard your business data.
Security Mechanisms and Approach
Innercircle Technology Pty Ltd prioritizes the privacy and security of your business data by adhering to industry best practices. Your data is securely stored using Microsoft Azure cloud infrastructure located in Australian data centers.
Microsoft Defender for Cloud
We utilize Microsoft Defender for Cloud to monitor security alerts and provide advanced threat protection for all Azure resources, including SQL databases, containers, web applications, and virtual networks. This tool detects unusual access attempts and malware uploads, ensuring comprehensive defense for our cloud environment.
Firewalls
Azure SQL Servers at HirePOS are safeguarded by firewall rules that restrict network traffic solely to the HirePOS web applications within the same data center. Data modifications are only permitted through direct user actions within the HirePOS applications.
Regulatory Compliance
All resources hosted by HirePOS on Microsoft Azure infrastructure comply with various regulatory standards such as PCI DSS 3.2.1, ISO 27001, and SOC TSP. The infrastructure undergoes continuous monitoring to maintain compliance.
Data Storage
Data Encryption
Your information is encrypted using industry-standard methods both in transit and at rest to protect personal and financial data. TLS/SSL encryption is employed for data in transit.
Databases and Data Segregation
HirePOS data is stored in separate Azure SQL Databases for each client subscription, ensuring data segregation and integrity. Each subscription has its own SQL database instance hosted in the Australia East location.
Backups
To prevent data loss and aid in disaster recovery, HirePOS Databases are backed up regularly through full, differential, and transaction log backups. Backup data is stored in geo-redundant storage blobs for enhanced protection.
Disaster Recovery
Data redundancy mechanisms are in place to protect against various events, ensuring data availability even in the face of hardware failures or natural disasters. Data is stored in geo-redundant storage blobs across multiple regions for disaster recovery purposes.
Users and Data Access
User Authentication
HirePOS requires two-factor authentication (2FA) as an additional layer of protection for user accounts.
At a minimum, users authenticate using a 2FA Verification Email, where a verification code is sent to the user's registered email address during sign-in.
For enhanced security, HirePOS also supports a native Authenticator App option. Users can scan a QR code to configure a compatible authenticator app and generate time-based verification codes when signing in.
HirePOS also supports Microsoft Single Sign-On (SSO) and Google Single Sign-On (SSO), allowing organizations to use their existing Microsoft or Google identity and multifactor authentication policies.
User Behavior and Practices
User practices significantly impact data security. Users should protect access to their registered email account, use the available two-factor authentication options, create strong and unique passwords, maintain appropriate malware protection, and never share passwords or authentication codes with other users.
Where available, using an Authenticator App, Microsoft SSO, or Google SSO with multifactor authentication is recommended for additional account protection.
Data Access
Your organization's data is protected, and access is restricted unless explicitly authorized.
HirePOS team members access customer data only where required to provide authorised support or services, and where appropriate, with your permission and under your supervision.
Service Reliability, SLA, and Uptime
HirePOS v5 Cloud relies on the reliable Microsoft Azure infrastructure with a typical uptime of 99.9%. While no system guarantees 100% uptime, we follow best practices to minimize downtime risks.
