Site Security Measures
Last updated August 8, 2024
1. Program
Hightouch will implement and maintain a comprehensive written information security program (“Information Security Program”), which contains appropriate administrative, technical and organizational safeguards that are designed to: (a) help ensure the security, integrity, availability, resilience and confidentiality of Personal Data; and (b) meet or exceed prevailing industry standards.
2. Access Controls
Hightouch will: (a) abide by the “principle of least privilege,” pursuant to which Hightouch will permit access to Personal Data by its personnel solely on a need-to-know basis; (b) promptly terminate its personnel’s access to Personal Data when such access is no longer required for performance under the Agreement; and (c) log the details of any access to Personal Data, and retain such records for no less than 90 days.
3. Account Management
Hightouch will use reasonable measures to manage the creation, use, and deletion of all account credentials used to access the Hightouch Systems, including by implementing: (a) a segregated account with unique credentials for each user; (b) strict management of administrative accounts; (c) password best practices, including the use of strong passwords and secure password storage; and (d) periodic audits of accounts and credentials.
4. Vulnerability Management
Hightouch will: (a) use automated vulnerability scanning tools to scan the Hightouch Systems; (b) log vulnerability scan reports; (c) conduct periodic reviews of vulnerability scan reports over time; (d) use patch management and software update tools for the Hightouch Systems; (e) prioritize and remediate vulnerabilities by severity; and (f) use compensating controls if no patch or remediation is immediately available.
5. Security Segmentation
Hightouch will monitor, detect and restrict the flow of information on a multilayered basis within the Hightouch Systems using tools such as firewalls, proxies, and network-based intrusion detection systems.
6. Data Loss Prevention
Hightouch will use reasonable data loss prevention measures to identify, monitor and protect Personal Data in use, in transit and at rest. Such data loss prevention processes and tools will include: (a) automated tools to identify attempts of data exfiltration; (b) the prohibition of, or secure and managed use of, portable devices; (c) use of certificate-based security; and (d) secure key management policies and procedures.
7. Encryption
Hightouch will encrypt, using industry standard encryption tools, all Personal Data that Hightouch: (i) transmits or sends wirelessly or across public networks or within the Hightouch Systems; (ii) stores on laptops or storage media, and (iii) stores on portable devices or within the Hightouch System. Hightouch will safeguard the security and confidentiality of all encryption keys associated with encrypted Personal Data.
8. Pseudonymization
Hightouch will, where possible and consistent with the Services, use industry standard and commercially reasonable pseudonymization techniques to protect Personal Data.
9. Secure Software Development
Hightouch will follow secure application development policies, procedures, and standards, including: (a) segregating development and production environments; (b) filtering out potentially malicious character sequences in user inputs; (c) using secure communication techniques, including encryption; (d) using sound memory management practices; (e) using web application firewalls to address common web application attacks such as cross-site scripting, SQL injection and command injection; (f) implementing the OWASP Top Ten recommendations, as applicable; (g) patching of software; (h) testing object code and source code for common coding errors and vulnerabilities using code analysis tools; (i) testing of web applications for vulnerabilities using web application scanners; and (j) testing software for performance under denial of service and other resource exhaustion attacks.
10. Physical Safeguards
Hightouch will maintain physical access controls designed to secure relevant Hightouch end-user workstations used to access any Personal Data on the platform.
11. Administrative Safeguards
Prior to providing access to Personal Data to any of its personnel, Hightouch will: (a) take reasonable steps to ensure the reliability of such personnel, including by performing background screening (to the extent permitted by Data Protection Law); and (b) provide appropriate security training to such personnel to ensure such personnel can comply with the obligations under this document. Hightouch will periodically provide additional training to its personnel as may be appropriate to help ensure that Hightouch’s Information Security Program meets or exceeds prevailing industry standards.