Security
Lansweeper manages the data of over 20,000 companies worldwide, and with this responsibility, we are committed to providing our customers with the highest standards of security.
We understand our responsibility when you, our customers, entrust us with a significant amount of data. To maintain customer confidence in our security posture and the security features we provide, we work diligently to continuously improve security processes and controls and provide our customers with the highest transparency they need.
Lansweeper's Approach to Security
Vulnerability Management
Application Security
Infrastructure Security
Our platform is hosted in both AWS and Azure. Following the “Shared responsibility model”, they are responsible for protecting the infrastructure that runs all of the services offered in the cloud. Our infrastructure is protected using multiple security mechanisms:
- Customer asset data is logically separated from other customer’s asset data in a multi-tenant environment;
- Comprehensive logging and monitoring on a 24/7 basis for operational and security-related issues and incidents;
- Firewalls to filter network traffic and enforce network segmentation;
- A web application firewall (WAF) for content-based dynamic attack blocking;
- Backups and high availability and resiliency services are in place to ensure no data is lost
- A disaster recovery plan is in place and is reviewed on an annual basis by relevant personnel. The disaster recovery plan is tested at least once a year.
All service providers supporting our cloud platform are subject to a review of available audit and certification reports to evaluate and confirm the security practices implemented.
Encryption
Lansweeper encrypts all data both in transit and at rest:
- Data in transit is encrypted using TLS;
- Data at rest is encrypted across our infrastructure using strong encryption protocols (AES-256);
- Credentials are encrypted using strong encryption before being added to your Lansweeper database.
Security awareness and training
All personnel is subject to and required to follow recurrent security awareness sessions during onboarding and employment via an automated security awareness program. Security awareness focuses on understanding the Lansweeper security framework and the current threats and risks all personnel should be aware of.