Eden Consulting Group servers are cloud based on AWS Cloud Servers based in Ohio. We maintain the system ourselves. Physical security is provided by AWS. AWS provides robust physical security measures for its data centers, including access controls, surveillance system and 24/7 monitoring. The physical infrastructure is designed to protect against unauthorized access, environmental risks, and power outages. AWS data centers comply with industry standards and certifications for physical security.
The following is a partial list of assurance programs with which AWS complies:
• SOC 1/ISAE 3402, SOC 2, SOC 3
• FISMA, DIACAP, and FedRAMP
• PCI DSS Level 1
• ISO 9001, ISO 27001, ISO 27017, ISO 27018
Snapshots as well as backups are taken at regular intervals and stored on independent systems. SQL and file backups are done every half hour and stored in an S3 bucket which is also encrypted, ensuring regular backups of your data. We also perform full instance backups daily and retain them for one month. All data is encrypted at rest.
The servers are housed in secure facilities that provide the following amenities and are managed by our own team.
SSL Security is provided by Starfield Root Certificate Authority - G2, as indicated by the green lock in the address bar you will find at KATSOnline.net. SSL Security (Secure Sockets Layer) provide an encrypted connection between your computer or browser and our servers.
Two factor authentication functionality. (Selectable Option)
Password hardening. (Selectable Option)
Hard lockout after 5 password attempts. (Requires user to contact support for reset.
Eden K9 Consulting & Training Corp continues to retain and keep your information secure after cessation of services for a minimum of two years. You retain full normal access to the services in order to obtain any needed reports. The system only restricts the client from adding additional data. During that time the client can download or print off any data required without being required to contact support.
Data Hosting and Cyber Security Approach
● Hosting Environment & Data Residency: All production servers and data repositories are hosted entirely in the AWS US-East (Ohio) region. We do not store, process, or backup customer data
outside the continental United States.
● Physical & Infrastructure Security: Physical infrastructure is managed and protected entirely by Amazon Web Services (AWS) data centers, which maintain strict 24/7 surveillance, multi-factor biometric access controls, and conform to standard enterprise assurance programs, including SOC 1/2/3 and ISO 27001.
Data Encryption
○ In-Transit: Every connection to katsonline.net is strictly encrypted using TLS 1.2 and TLS 1.3. We utilize a public high-assurance Extended Validation (EV) SSL certificate. Connections deploy HTTP Strict Transport Security (HSTS) with a long preloaded duration and prioritize secure cipher
suites.
○ At-Rest: Databases, static file attachments, and historical backups are encrypted utilizing AES-256 encryption keys managed via AWS Key Management Service (KMS).
Cybersecurity Operations & Vulnerability Management:
○ Web Application Firewall (WAF): Deployed at the edge to mitigate OWASP Top 10 web vulnerabilities.
○ Regular Security Scanning: Automated external vulnerability scans are conducted quarterly by Security Metrics using specialized ASV sensors to identify misconfigured assets, bad IPs, or software vulnerabilities.
○ Secure Development: Development is managed alongside Amplify Communications Group using a secure Software Development Life Cycle (SDLC) that mandates developer peer code reviews, automated code analysis, and alignment with NIST's Secure Software Development Framework (SSDF).
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.