Security and Redundancy Overview Summary

Version 4

FacilityOS Solution Overview

Introduction

FacilityOS is an enterprise-grade product developed, hosted and tested using the highest industry standards, exceeding most requirements.

FacilityOS is a cloud-based secure facility management system comprising a self-serve device or kiosk and centralized hosting. The entire solution is managed through the web-based portal which allows administrators to manage the specific features and details of each installation as well as generate reports pertaining to the visitor activity at each site.

This document serves as a review of provided technology with emphasis on the security and redundancy of the solution.

Following is a summary; detailed Technology Review document is available on request, pending executed NDA. Certain items require specific license subscriptions and/or may be subject to additional costs.

Our Employees and Workspace Environment

  • All FacilityOS employees are screened with extensive background and criminal record checks prior to hiring.
  • All employees are trained in the company’s privacy, safety, security and other workplace policies.
  • All equipment and data handling follows common security practices:
    • Applications and hardware are inventoried.
    • Access is role based with global policies enforced (Active Directory).
    • Ports are blocked.
    • Production data is not locally stored.
    • Devices are tracked and centrally managed.
How We Built FacilityOS
  • FacilityOS is designed and built in Toronto, Canada.
  • We follow Agile and Scrum methodology.
  • We adhere to OWASP Secure Coding Practices (www.owasp.org).
  • All software development is version and source controlled.
  • Three separate environments are maintained (Production, Development, Staging) with restricted access.
  • Our development teams do not have access to customer data.
  • Microsoft Technologies are used to control access (Azure Active Directory).

Your Data Security, Privacy and Confidentiality

  • All customer data is considered private and confidential and is protected by the privacy policy.
  • Custom agreements and privacy policies are available.
  • Customers can elect to have the data stored in a specific geo-location.
  • Customers can request custom data retention policies; expired data is deleted using automated database  procedures, DOD 5220.22M available on request.
  • All data is fully encrypted at rest and during transmission.
  • All access is controlled and monitored.
  • Customer data is segmented, and access is limited to owner(s) only.
  • Passwords are hashed and cannot be recovered.

Visitor Data Security, Privacy and Confidentiality

  • Visitor data falls under the main system guidelines for data security.
  • Global data privacy standards are supported (i.e. GDPR).
  • FacilityOS offers a strong compliance platform which plugs into an organization’s global compliance initiatives, implementation of which is managed by the Client.
  • Geo-distributed data storage is available to comply with local rules.

Product, Security, Continuity

  • FacilityOS is hosted on Microsoft Azure (Multiple GEO locations available). Additional hosting options are available utilizing local vendors and our own dedicated hosting environments.
  • All data centers adhere to common industry standards for data protection and policies. Certifications are geo/site specific and cover PCI DSS, ISAE 3402 Type II, SOC 2 Type II and CSAE 3416 Type II to name a few.
    Please visit Azure trust center for a list of supported certifications and standards: https://azure.microsoft.com/en-us/support/trust-center/
    Non-Azure hosted, site specific certifications are provided on request.
  • Geo/region specific hosting is available.
  • Data and services are fully backed and are fully redundant with an availability of 99.9%  uptime guarantee.
  • Server / Platform structure is hosting dependent and available on request.
  • FacilityOS supports Offline mode (no network connection).
  • FacilityOS packages can be deployed with a fully redundant cellular connection.

More on Encryption

  • All access to web services uses HTTPS (TLS 1.2+).
  • Device to server communication is encrypted with a private key, delivered over secure channel (HTTPS) and tokenized using device unique identifier and other undisclosed variables.

Connectivity

  • FacilityOS can be deployed using a combination of cellular, wireless, and ethernet connections. Exact configuration is dependent on each client’s redundancy and hardware requirements.
  • FacilityOS uses standard ports and services which makes it a “plug ‘n play” product when connected to the client’s infrastructure. In most cases, no additional configurations are required.
  • Clients managing highly restricted environments will need to ensure that traffic to *.goilobby.com bypasses proxies and is whitelisted on the firewall(s).
  • In some cases, subject to client’s wireless network policies, FacilityOS may need to be provisioned with client’s wireless network certificates.
  • We recommend setting up all equipment using static IPs. This makes for a more robust and stable setup. Our preference is to let the client’s DHCP server assign static IPs using provided MAC addresses.

Subcontractors and Third Parties

  • FacilityOS core engineering function is completely in-house, in our Toronto office.
  • The use of any subcontractors puts them in scope of our overall standards for security and privacy. Specifically:
  • Each subcontractor must be classified based on their risk.
  • Their policies and standards must meet our requirements.
  • Their policies and standards must be reviewed as frequently as required by their classification within our policies and controls.
  • FacilityOS requires the use of Third Parties for provision and delivery of some of its services. Specifically:
    • Microsoft Azure – hosting provider for the FacilityOS Platform

We encourage customers to review the above-mentioned content for compliance with their internal requirements.

Payments

  • All credit card transactions are processed in a PCI-DSS certified environment to ensure compliance and security. 

Insurance

  • FacilityOS employs business continuity, data theft and breach insurances covering liability in excess of $2,000,000. Certificate available on request.