OfficeSpace

OfficeSpace Security Overview

OfficeSpace ensures enterprise security through multi-layered measures including role-based access controls with two-factor authentication, AES256 encryption of data at rest and in transit, regular third-party penetration testing, integrated DevSecOps practices, continuous network and application monitoring, infrastructure hosted by SSAE 16/18 and ISO 27001-compliant providers, and comprehensive employee security and privacy training.

Security for Enterprise Teams

OfficeSpace provides robust security and industry-standard compliance solutions to mitigate risk and protect your data from costly breaches. Key features include:

  • Highest-level security for networks, data, and employees
  • Industry-standard compliance solutions
  • Rigorous data privacy for both OfficeSpace and its clients
  • Enhanced AI that maintains security

Encrypted, Tested, Controlled

OfficeSpace employs a multi-layered approach to security, including employee training, technology processes, and best practices.

Access Controls

  • Employee access levels: Access is granted based on role and training, with unique identifiers for accountability. Access is revoked upon termination.
  • Authentication: Employees use password managers, strong passphrases, and two-factor authentication for sensitive systems.

Data Encryption

  • At rest and in transit: Data is encrypted in transit (HTTPS/TLS 1.2+) and at rest (AES256).

Proactive Protection

  • Penetration testing: Regular third-party testing to identify security or privacy concerns.
  • DevSecOps: Security practices such as DAST and SAST are integrated into application and infrastructure deployments.
  • Monitoring: Networks, servers, and applications are proactively monitored for malware and vulnerabilities, including nightly scans and endpoint protection.
  • Review and evaluation: The security team reviews vulnerabilities, categorizes threats, and prioritizes patches.

Secure Networks and Infrastructure

  • Network security: Use of Single Sign-On (SSO), Multi-Factor Authentication (MFA), Host Intrusion Detection, virus and malware protection, local and network-level firewalls, and Access Control Lists.
  • Company infrastructure protection: Applications and services are monitored for suspicious activity. Infrastructure is hosted by SSAE 16/18 and ISO 27001-compliant providers.

Employee Training

  • Security and privacy training: All employees receive initial and ongoing security training.

Patch Testing and Verification

  • Risk and assessment testing: Patches are tested before deployment; emergency patches may be deployed within 24 hours.
  • Audit, assessment, and verification: Patch installation is verified and coordinated with technology teams to ensure no adverse effects.

Enhanced Data Privacy

OfficeSpace implements rigorous measures to protect personal and sensitive data, adhering to U.S. and international privacy laws and standards.

Regulatory Adherence

  • Legal compliance: Policies are developed in collaboration with legal professionals to ensure regulatory compliance.
  • Data privacy: Privacy by-design measures protect personal and confidential data, ensuring confidentiality and integrity.

Auditing and Reporting

  • Security and compliance assessments: Internal assessments are conducted, and a SOC2 compliance audit report is maintained.

Transparent Data Collection

  • Data requests: Data Processing Agreements (DPA) are established with Data Controllers and Sub-processors to protect Data Subjects' rights.

Trusted Third-Parties Only

  • Third-party suppliers: Suppliers are assessed and evaluated to ensure a strong security posture.

“Creating trust with our users is the objective. Maintaining that trust is a daily recurrence.”

Jorge M. Diaz, Head of Infosec at OfficeSpace

Jorge M. Diaz (JD) brings over two decades of experience in Information Security and Privacy, including leadership roles at LifeWorks and Morneau Shepell (now Telus Health). He is committed to advancing information security and privacy standards at OfficeSpace.

Industry-Standard Compliance

OfficeSpace is committed to protecting sensitive information through internal and third-party security and compliance testing, and by working with legal professionals to ensure regulatory adherence.

Data Minimization

  • Classifying and inventory data: Data is categorized by sensitivity and access requirements. Access control ensures only necessary employees access certain data levels.

Best Practices for Data Protection

  • Protecting data: Practices include data segregation, access control, auditing, and ongoing risk evaluation.
  • Data and media disposal: Data is stored according to regulatory requirements and retention schedules. Data can be returned or de-identified upon request.

Security Documentation

  • Public trust profile and catalog: Detailed security and compliance information is available upon acceptance of a Non-Disclosure Agreement (NDA).

Secure, Ethical AI

OfficeSpace is committed to responsible AI development, prioritizing the responsible collection and use of private data.

Strict Adherence to Standards

  • Compliance with global data protection standards and regulations.

Anonymization and Encryption

  • Robust techniques are used to mask individual identities and protect user privacy.

Transparency and Control

  • Clients have clear controls over their data and access to transparent documentation about data handling practices.

Fairness and Equity

  • AI solutions are designed to support diverse work styles and preferences, ensuring fairness and inclusivity.

OfficeSpace is Trusted by Cybersecurity Experts

OfficeSpace is recognized and trusted by cybersecurity experts and organizations for its commitment to security and privacy.