Certifications

At 3 Story Software we consistently tests our cloud based software and internal systems with penetration testing and audits to make sure we are operating above best practices in the industry.

ISO 27001

This framework determines whether an organization has built an information security management system (ISMS) capable of protecting sensitive data. This certification reviewed how 3SS stores and retrieves data, how we assess and mitigate risks, and how we continuously improve data security. An independent auditor has affirmed that 3 Story Software's ISMS meets the standards for ISO 27001 certification.

 

SOC 2 Type II

System and Organization Controls (SOC) as defined by the American Institute of Certified Public Accountants (AICPA), is the name of a suite of certifications aimed at measuring and testing internal controls, capturing how a company safeguards customer data and how well those controls are operating.

 

GDPR

The General Data Protection Regulation is a regulation in EU law on data protection and privacy in the European Union and the European Economic Area. Since 3SS is a global company and our customers do business around the world, almost all of them our affected by GDPR. We set up our application to meet all of the GDPR guidelines.

 

Certified Azure Data Centers

Microsoft Azure is the best in their class, having spent over a billion dollars on their security infrastructure. Our partnership with Microsoft Azure allows us to have granular control of our virtual environment and 24-hour monitoring with intrusion detection and DDoS.

 

Annual Penetration Testing

We contract an outside firm to conduct an annual penetration test of our application, and we have the cloud network tested 4 times a year for vulnerabilities.