Our security practices

We encrypt all your data, both at rest and in motion

Each person and each company using Federated Directory expects their data to be secure, confidential, and private. We understand how important this is to our customers and work to the best of our abilities to ensure all three expectations are met. Please review the information below regarding our current policies and practices, along with our Privacy Policy and Terms of Service. This is a living document and we will update it as our service evolves and industry practices change.

Security

As a company, we use the Federated Directory service for nearly all of our communication. Ensuring that the Federated Directory service remains secure is vital to protecting our own data. The security of your information is required for our success as a business. Below are some details on our security practices. The security safeguards that we use to protect your data vary based on the sensitivity of the information that we collect, process and store and the current state of technology.

Encrypted traffic by default, in both directions

Federated Directory uses 128-bit AES, supports TLS 1.2 for all in flight data, and uses the ECDHE_RSA Key Exchange Algorithm. We monitor the security community's output closely and work promptly to upgrade the service to respond to new vulnerabilities as they are discovered.

Encrypted stored data by default

All your company's user and contact data is encrypted. Our database platform is SSAE 16, ISO 27001, PCI DSS v3.0, and HIPAA compliant.

Two factor authentication and single sign on

If you connect your Google Workspace or Microsoft environment with Federated Directory, you and your users will be able to log in to our services by using your current Google or Microsoft accounts. Two factor authentication can be enabled on these services. If you use our internal directory, you can setup Single Sign On (SSO) authentication. We use SAML2.0 or OpenID Connect to connect to your IDP. Depending on your IDP, you can enable two factor authentication again.

Secure physical location

Our servers are located in Google Cloud Compute data centers. They've devoted an entire portion of their site to explaining their security measures, which you can find here: https://cloud.google.com/security

Experienced team

Even before Federated Directory, we've been putting services on the internet for a long time. We're good at it. Our engineering, quality assurance and technical operations team members are experienced and keep their skills up to date as industry best practices evolve. We've coded, tested and administered services running on lot's of servers in data centers around the world and we bring the collective wisdom that comes with many decades of secure practice to the operation of the Federated Directory service.

Security features for team members and administrators

The highest security risk to any system is usually the behavior of its users. We want to provide you with the tools you need to protect your own data. For example, we log every time information within your Federated Directory is changed and by who. These logs are available to you. We will continue to roll out additional features which afford you more control over the security of your own Federated Directory.

Availability

We understand that you rely on Federated Directory to work. We're committed to making Federated Directory a highly-available, ultra-reliable service that you can always count on. We build systems that tolerate the failure of individual computers or whole datacenters, keep many copies of your data online for redundancy, practice disaster-recovery measures often, and always have staff on-call to quickly resolve unexpected incidents.

Confidentiality

We regard the information you share within your Federated Directory team as private and confidential to your team. We place strict controls over our employees' access to internal data and are committed to ensuring that your data is never seen by anyone who should not see it. While the operation of the Federated Directory service would not be possible unless there were some technical employees with sufficient system permissions to enable them to access and control software that stores and indexes the content you add to your Federated Directory team, this team is kept purposefully small and are prohibited from using these permissions to view customer data unless it is necessary to do so. All of our employees and contractors are bound to our policies regarding customer data and we treat these issues as matters of the highest importance within our company. If, in order to diagnose a problem you are having with the service, we would need to do something that would expose your personal communications to one of our employees in a readable form, we will ask for your consent prior to taking action. Our platform will automatically generate an audit entry of any such access. There are limited circumstances when we ever share customer content without first obtaining permission. These are outlined in our Privacy Policy.

Privacy

A fundamental privacy principle we abide by is that by default, anything you post to Federated Directory is private to your team. That is, viewing the messages and files shared within a specific team requires authentication as a member of that team. Federated Directory has a comprehensive Privacy Policy that lays out our approach to privacy. Please take a moment to read it. Also please read our knowledge base to learn more about topics such as: How to configure which data we store synchronize from your corporate address book How to set the data your company makes available to another company through a federation If you are using Federated Directory in a workplace or on a device or account issued to you by your employer or another organization, they will most likely have their own policies in place regarding storage, access, modification, deletion and retention of communications and content. Please check with your employer or team administrator about what policies they have in place regarding your communications and related content.

We know how important these issues are to you. They are equally important to us. The security, privacy and confidentiality of your information are core to our success as a business and we will continue to be proactive, vigilant and diligent in ensuring its safety. If you have additional questions regarding data privacy, security or confidentiality, we'd be happy to answer them. Please write to support@federated.directory and we'll respond as quickly as we can. If you believe you have found a security vulnerability on Federated Directory, we encourage you to let us know right away. We will investigate all legitimate reports and do our best to quickly fix the problem.

Effective date

27 January 2024