Aller au contenu

Security

Where your files live, and who can reach them

Your library sits in encrypted storage on AWS, inside a network of its own, behind the access rules you set. None of that is finished work — we patch on a schedule, scan for vulnerabilities and have the platform penetration tested.

How it is configured

Today

Sign-in

Two-factor or SSO

In transit

TLS 1.2 / 1.3

At rest

Encrypted on S3

Network

Isolated VPC

OngoingPatched on a schedule, scanned, and penetration tested

A summary — ask us for the detail

Who gets in

Most incidents are an account, not an exploit. Sign-in is the control you will use most, so it is the one with the most ways to tighten it.

  • 01

    Two-factor, or your own identity provider

    Turn on two-factor authentication, or hand sign-in to the SSO provider your organisation already runs. Email link validation and captcha verification stand in front of the login either way.

  • 02

    Personal data you can get back out

    We collect no personal data without consent, and our data protection officers remove it on request. GDPR is the standard the platform is built to; PDPA is the one our Asian clients are held to.

What happens to your files

An archive is only as good as the copy you can still open in five years. Three things stand between your files and that going wrong.

  • 01

    Stored on AWS S3

    Amazon designs S3 for eleven nines of durability, across data centres with layers of physical security in front of them. Your originals sit there at the resolution you uploaded, not on a server under someone’s desk.

  • 02

    Backed up, and restorable

    Disk snapshots and database backups run on a schedule, so a bad day is a restore rather than a loss. We test that they come back.

  • 03

    Scanned on the way in

    Every uploaded file goes through anti-malware scanning before it reaches your library, so nothing sits in your archive waiting for a colleague to download it.

What stands around them

The infrastructure is ours to look after. This is what that means, for anyone whose security questionnaire asks.

  • 01

    A network of your own

    Each client’s infrastructure is isolated inside its own Virtual Private Cloud, with tight access control lists on every route in. Traffic between AWS endpoints stays on the private network and never crosses the public internet.

  • 02

    A firewall in front of the application

    A web application firewall filters incoming traffic, blocks application-level attacks, and helps detect and absorb attempts to flood the service.

  • 03

    Encrypted in transit and at rest

    TLS 1.2 and 1.3 on every connection to the platform, VPN for access to internal infrastructure, and encryption on archive storage.

  • 04

    Watched, with alerts that go to people

    Monitoring for downtime, unexpected latency and packet loss, plus alerts on certificate events and changes to infrastructure configuration.

On request

Ask for the detail

Buying software like this usually means a security review, and a page is no substitute for the document your team actually has to file. Send us the questionnaire and we will fill it in — or talk to the person who runs the infrastructure rather than to someone relaying the answers.

What we can send

  • A summary of our most recent penetration test
  • Our patching and vulnerability scanning schedule
  • Where your data is hosted, and in which region
  • How to reach our data protection officer
  • What we delete, and when, if you ask us to

Next step

We’d love to explain more…

Still got questions? Curious to see LightRocket in action? Want to know more about pricing?

We’re always happy to show off our system and, yes, we’ll even help out with discounts and pricing.

Pour une meilleure expérience sur LightRocket, nous vous recommandons d'accepter tous les cookies. Cependant, nous respectons votre vie privée et vous pouvez choisir parmi les options ci-dessous :

Ces cookies sont indispensables pour utiliser LightRocket.

Ces cookies nous aident à comprendre votre comportement sur le site et sont utilisés uniquement à des fins d'analyse et de recherche.

Ces cookies sont partagés avec des tiers de confiance pour une expérience publicitaire personnalisée.