We review all aspects of our processes to ensure the integrity and security of our client’s data. We review security within three separate segments of the service.
Customer Location
Usernames and passwords - Our software can be configured post-install with a username and password. This username and password must be entered each time to gain access to our software.
Data Transmission
Proprietary software format used - All client data is transmitted in the proprietary Info Exchange software format, as well as being compressed and encrypted. Without a properly authorized DataVault-Client installation, the data is unreadable.
Encryption
To insure the security of our client’s data, our software automatically encrypts every file it sends over the internet with an encryption key provided by the client during the installation process. Info Exchange utilizes US Government approved encryption algorithms to generate its public and private key pairs and supports an industry leading key size up to 256 bits.
All of the client’s files are stored and remain encrypted on our secure data vaults at all times. The decryption process occurs automatically during the restore operation by our software at the client site. All client data therefore is encrypted before it leaves the client site and not decrypted until it is back at the client site. This ensures that all backup data transferred and stored outside the client’s location is always protected.
Note: Info Exchange cannot reset encryption keys nor do we retain encryption keys for end-users.
Block level changes
After the initial seed backup Info Exchange creates a customer specified number of versions based upon block level changes. The software completes a review process during each backup set which recognizes and captures block level changes to files since the last backup. Only the changed blocks are processed offsite for retention.
Block level changes enhance security by only sending bits and pieces of data to complete a daily full backup. Complete files are not sent, only fragments of files which would be unusable without the seed data.
Info Exchange Data centre
Physical security
All client data resides in its encrypted format behind the firewall. In addition, our Data Vaults reside in a secure state-of-the-art co-location facility with redundant internet bandwidth, power, and backup generators. Physical access to our system is guarded by three separate pass key entrances and each Data Vault is within a locked cabinet.
Facility redundancy
Complete redundancy for bandwidth and power are a mandatory requirement for all facilities in which our Data Vaults are located. For example: The Marlboro, Massachusetts Data Vault maintains 2 separate bandwidth providers for constant internet availability and capacity. In addition, dual conduits in to the building for both power and bandwidth are utilized. Power is support by UPS, battery backup and diesel generators and utilizes an automatic transfer switch to transfer power in the event of an emergency.