Enterprise-level security and compliance
Suralink inherently understands the importance of data security and has built enterprise-level security into every aspect of the platform.Request a Demo
Protecting sensitive client data
You and your team handle sensitive client information every day, including financial, personal, payment data, and more. Ensuring that data remains secure is critical for both your clients’ and your business’s long-term success.
Encrypted third-party access
Access restriction by role or engagement
SSL AES 256-bit encryption
SSAE16 Type II SOC1, SOC2 compliant data centers
Encryption for the modern business
All documents that are uploaded into Suralink are always secured with AES-256 bit encryption. Client organization names, engagement names, and all comments between users are treated as sensitive and are also encrypted at rest with AES-256 bit encryption.
Recovery, backup, and audit logs
Accidents happen and sometimes you need to review, recover, or audit your data. To that end, all data stored in Suralink is encrypted and backed up offsite daily. A two-stage “click then confirm” deletion system prevents accidental data deletions. And an audit trail logs all activity in the system by username and IP address.
Rigorous third-party testing
To ensure the highest levels of security, we perform vulnerability and penetration security tests on a regular basis. These include internal and external scans from multiple third-party experts.
Remembering 20 different passwords for 20 different applications is hard. But that’s no reason to be lax about security. Suralink has strict password requirements to ensure every login is as secure as possible.
Suralink offers all users the option to use third-party mobile authenticators to protect their account. Administrators can also require team members to have two-factor authentication enabled.
Session inactivity and timeout
Every Suralink account is protected by session inactivity and timeout protocols. If you’ve been inactive for too long, we’ll log you out automatically to protect your data and ensure no one else can access your account.
Meeting data security standards across industries
Whether you work with clients in the healthcare or retail industries, the financial sector or high tech, we’re compliant with the latest rules and regulations. You can feel secure knowing that our data privacy protections meet the most stringent compliance standards.
Developed by the American Institute of CPAs (AICPA), SOC 2 defines criteria for managing customer data based on five “trust service principles”—security, availability, processing integrity, confidentiality and privacy.
The California Consumer Privacy Act (CCPA) is a state-wide data privacy law that regulates how businesses all over the world are allowed to handle the personal information (PI) of California residents. Suralink currently adheres to all CCPA requirements.
The General Data Protection Regulation (GDPR) is a legal framework that sets guidelines for the collection and processing of personal information from individuals who live in the European Union (EU). Suralink is currently compliant with GDPR guidelines.