OmaxTelecom
Security, privacy, and reliability information for eSIM and white-label, SMS and SMPP, API, and voice services. For documentation or questions, contact our security team directly.
Safeguards
Controls
How we design and operate security across our platform and services.
- 36 controls
- By security area
Status icons indicate a control described on this page. They are not an independent audit or certification.
Infrastructure security
Database replication utilized
The company's databases are replicated to a secondary data center in real-time. Alerts are configured to notify administrators if replication fails.
Published statementProduction data backups conducted
The company performs periodic backups for production data. Data is backed up to a different location than the production system.
Published statementUnique production database authentication enforced
The company requires authentication to production datastores to use authorized secure authentication mechanisms, such as unique SSH keys.
Published statementEncryption key access restricted
The company restricts privileged access to encryption keys to authorized users with a business need.
Published statementUnique account authentication enforced
The company requires authentication to systems and applications to use unique usernames and passwords.
Published statementProduction data segmented
The company prohibits confidential or sensitive customer data, by policy, from being used or stored in non-production systems or environments.
Published statementProduction application access restricted
System access is restricted to authorized access only.
Published statementAccess control procedures established
The company's access control policy documents the requirements for adding new users, modifying users, and removing an existing user's access.
Published statementProduction database access restricted
The company restricts privileged access to databases to authorized users with a business need.
Published statementFirewall access restricted
The company restricts privileged access to the firewall to authorized users with a business need.
Published statementProduction OS access restricted
The company restricts privileged access to the operating system to authorized users with a business need.
Published statementProduction network access restricted
The company restricts privileged access to the production network to authorized users with a business need.
Published statementAccess revoked upon termination
The company completes termination checklists to ensure that access is revoked for terminated employees within SLAs.
Published statementUnique network system authentication enforced
The company requires authentication to the production network to use unique usernames and passwords or authorized Secure Shell (SSH) keys.
Published statementRemote access MFA enforced
The company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.
Published statementRemote access encryption enforced
The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection.
Published statementLog management utilized
The company utilizes a log management tool to identify events that may have a potential impact on the company's ability to achieve its security objectives.
Published statementInfrastructure performance monitored
An infrastructure monitoring tool is utilized to monitor systems, infrastructure, and performance and generates alerts when specific predefined thresholds are met.
Published statementNetwork segmentation implemented
The company's network is segmented to prevent unauthorized access to customer data.
Published statementNetwork firewalls reviewed
The company reviews its firewall rulesets at least annually. Required changes are tracked to completion.
Published statementNetwork firewalls utilized
The company uses firewalls and configures them to prevent unauthorized access.
Published statementNetwork and system hardening standards maintained
The company's network and system hardening standards are documented, based on industry best practices, and reviewed at least annually.
Published statementService infrastructure maintained
The company has infrastructure supporting the service patched as part of routine maintenance and as a result of identified vulnerabilities to help ensure that servers supporting the service are hardened against security threats.
Published statement
Organizational security
Asset disposal procedures utilized
The company has electronic media containing confidential information purged or destroyed in accordance with best practices, and certificates of destruction are issued for each device destroyed.
Published statementProduction inventory maintained
The company maintains a formal inventory of production system assets.
Published statementPortable media encrypted
The company encrypts portable and removable media devices when used.
Published statementAnti-malware technology utilized
The company deploys anti-malware technology to environments commonly susceptible to malicious attacks and configures this to be updated routinely, logged, and installed on all relevant systems.
Published statementEmployee background checks performed
The company performs background checks on new employees.
Published statementCode of Conduct acknowledged by employees and enforced
The company requires employees to acknowledge a code of conduct at the time of hire. Employees who violate the code of conduct are subject to disciplinary actions in accordance with a disciplinary policy.
Published statementConfidentiality Agreement acknowledged by contractors
The company requires contractors to sign a confidentiality agreement at the time of engagement.
Published statementConfidentiality Agreement acknowledged by employees
The company requires employees to sign a confidentiality agreement during onboarding.
Published statementPerformance evaluations conducted
Company managers are required to complete performance evaluations for direct reports at least annually.
Published statementPassword policy enforced
The company requires passwords for in-scope system components to be configured according to the company's policy.
Published statement
Data and privacy
Data retention procedures established
The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data.
Published statementCustomer data deleted upon leaving
The company purges or removes customer data containing confidential information from the application environment, in accordance with best practices, when customers leave the service.
Published statementData classification policy established
The company has a data classification policy in place to help ensure that confidential data is properly secured and restricted to authorized personnel.
Published statement
Questions about a control? Email [email protected].