Security
Introduction
We appreciate that many, if not all, of our clients and prospective clients have developed custom security questionnaires for their vendors. Unfortunately, Nilear is a small business with finite resources and cannot complete each questionnaire and spend Q&A time with each security officer. We do take security seriously; we just cannot dedicate resources to talk to each customer regarding their formal or informal questionnaire at this time.
We have compiled a list of common questions and answers regarding Nilear security. We hope that this list has enough to answer your security questions regarding Nilear. We have not answered certain questions that we feel would provide too much information for bad actors. For example, specifying what firewalls we deploy, what logs we keep or where do we store our encryption keys.
Vendor Information
Company Name | Nilear, LLC
EIN | 46-1451539
Address | 292 Main St, #284, Harleysville PA 19438 USA
Company Size | < 10
Email | support@nilear.com
Insurances and Certificates
Do you comply with current Data Protection Legislation? (DPA 2018/GDPR) | Yes
Do you hold any Security Certifications | Yes, we are SOC 2 Type 2 certified
Liability/Cyber-security Insurance | $1,000,000
System Security
Does the system suport Multifactor Authentication (M365/Google SSO)? | Yes (Required)
Where is the data physically stored? | TierPoint Colo, Valley Forge, PA USA | ISO 27001, SOC 1 Type II & SOC 2 Type II, HIPAA/HITECH, GLBA, PCI DSS v3. 2.1, NIST SP 800-53, SOC 2 + HITRUST, ITAR, and Privacy Shield.
Is the data encrypted at rest? | Yes
Controls against malware? | Firewall, OpenDNS, and Server-based anti-virus protection
Backup Information | All server instances are Hyper-V replicated and backed up using Azure Backup
Patching Policy | All servers are patched once a month.
Are the servers publicly accessible? | Only the front-end webservers are exposed to the Internet. All other resources require a private VPN for access.
Who has access to system data? | Direct access to the servers is limited to only two individuals. All of Nilear’s own company data is stored separately in the cloud so general Nilear employees are not granted access to our application servers.
How is your security layered? | First, only our front-end apache web servers have a port open to the Internet. Next, these front-end servers then communicate with separate application servers. Finally, these application servers communicate with the separate backend database. Direct server access is limited to private VPN access only. All network traffic to and from external sources are encrypted.
What information is stored? | ConnectActive Only
ConnectActive does not store customer or customer’s contact information in its database. Instead, ConnectActive stores ConnectWise Manage’s primary keys for your companies and contacts and uses one-way hashes for usernames and email addresses. Access to the customer’s Office 365 / Azure AD is granted by an Administrative delegate and can be removed using the tenant’s Office 365 / Azure AD portal. Active Directory integration can be terminated by removing the Scheduled Task for the Powershell Script.
Full Subscription Services
Services outside of ConnectActive can store sensitive data in order to provide necessary functionality. For example, the My Tickets module stores a warehouse table of live ticket information in order to improve performance and the Score My Team module stores time entry information in order to perform timesheet analysis.
How long is data retained? | Data older than two years of age is automatically purged from our system every four hours. Clients who have discontinued their subscription may have their data removed earlier. Discontinued clients can have their data removed immediately upon request.
Does your system require daily authentication? | The client can choose between no expiration for a logged in session or choose a 4 or 8 hour session timeout. This settings is applied to all members of the client’s company.
Do you have vulnerability testing performed? | Yes, vulnerability tests are performed monthly.
Other Vendor Dependencies | TierPoint, Microsoft, Chargify, Authorize.NET, Calendly, and ConnectWise are Nilear’s only technical vendors.
Employee Security
Do you perform background checks on employees? | Yes
Is employee access to data limited to their individual role? | Yes
Are the employees required to have anti-virus software installed? | Yes + OpenDNS
Is Nilear’s data and the customer’s data stored and secured separately? | Yes
Have Nilear employees been trained to avoid phishing and other entrapment techniques? | Yes
Do you have a password expiration policy? | No. Our philosophy is to apply M365/Google SSO to protect all systems rather than requiring passwords to expire.
Do you have a complex password requirement policy? | No. Again, our philosophy is to apply M365/Google SSO to protect all systems.
General Questions
What is required for integration? | Nilear will require you to create a Security Role and a Member API account within your ConnectWise PSA instance.
What ConnectWise PSA rights are required? | The rights required depend on the modules included under your subscription. For ConnectActive only subscriptions, will require a Security Role with Company and Agreement rights. Other modules will require more extensive rights.
For ConnectActive, what Office 365 rights are required? | You will need to grant ConnectActive read-only rights to user, group, and licence information for the client tenant using an administrative delegate account.
For ConnectActive, what Active Directory rights are required? | Active Directory sync is performed using a Powershell Script that is downloaded and installed by the MSP. The Powershell script performs a read-only operation to retrieve User, Group, and OU information.
Do you have SSO available? | Yes
