OfficeSpace

Security & Privacy

OfficeSpace Software, a hybrid workplace management platform, prioritizes robust security and privacy through comprehensive employee training, role-based access controls, SOC2 compliance, regular third-party penetration testing, legal reviews, data processing agreements, and proactive network monitoring, with detailed security documentation available under NDA.

OfficeSpace Software Security & Privacy Overview

OfficeSpace Software is a workplace management platform designed to support hybrid work environments. The company emphasizes robust security and privacy practices to protect its customers and their data.

Detailed information about OfficeSpace’s security and compliance is available in their Public Trust Profile and Catalogue. Access to certain documentation (such as SOC2 Report, SIG Core/Lite, VSA Core, CAIQ, infrastructure diagrams, penetration test reports, and policies) requires acceptance of a Non-Disclosure Agreement (NDA).

Security and Privacy Training

  • All employees undergo security training during their first week, covering security practices and procedural policies.
  • Employees are encouraged to report vulnerabilities or bugs promptly.
  • Ongoing security training is required several times a year to reinforce best practices and compliance.

Employee Access Levels

  • Access to internal systems is role-based and depends on completed training.
  • Unique access identifiers are used for accountability.
  • Employees must sign confidentiality agreements and acknowledge security policies before gaining access.
  • Access is revoked immediately upon termination.

Security and Compliance Assessments

  • Internal tests are conducted at every development stage.
  • OfficeSpace maintains a SOC2 compliance audit report.

Data Requests

  • Data Processing Agreements (DPA) are established with Data Controllers and Sub-processors to protect Data Subjects' rights.

Legal Compliance

  • Security and privacy standards are reviewed by internal and external legal professionals to ensure compliance with legal and regulatory requirements.

Penetration Testing

  • Regular penetration and vulnerability testing is conducted with third-party providers.
  • Reported incidents are prioritized and patched promptly.
  • Customer-reported concerns are evaluated and resolved quickly.

Monitoring

  • Proactive monitoring of network, servers, and applications for malware, breaches, and vulnerabilities.
  • Nightly network scans and individual website monitoring.
  • Endpoint virus and malware protection with real-time scanning and updates.

Review and Evaluation

  • Security incidents are reviewed within hours of notice.
  • Threats are categorized as Emergency, Critical, Not Critical, or Not Applicable.
  • All security patches follow a defined deployment process: risk assessment, testing, scheduling, installation, and verification.

Risk and Assessment Testing

  • Patches are assessed for impact before deployment.
  • Emergency vulnerabilities may be patched within 24 hours after successful testing.
  • Critical and Not Critical vulnerabilities undergo thorough testing before implementation.

Audit, Assessment, and Verification

  • After patch deployment, the security team verifies installation and checks for adverse effects on systems.

Protecting Data

  • Practices include data segregation, encryption, access control, and auditing to prevent unauthorized access and identify risks.

Authentication

  • Employees use password managers for complex credentials.
  • Strong passphrases are required.
  • Two-factor authentication is used for systems with production data.
  • Temporary SSH keys, device-specific tokens, and rotating keys are employed for secure access.

Classifying and Inventory Data

  • Data is categorized by sensitivity and access needs to control permissions.

Company Infrastructure Protection

  • Monitoring tools detect suspicious code, configurations, and user behavior.
  • IT specialists escalate incidents to the Security Team for resolution.
  • Infrastructure is hosted with globally recognized cloud providers (SSAE 16/18, ISO 27001 compliant).

Data and Media Disposal

  • Data retention depends on regulatory requirements and internal schedules.
  • At the end of the retention period, customers can request data return or deidentification.

Data Encryption at Rest and in Transit

  • Encryption is used for data transmission over public networks and for data at rest.
  • Systems are built on encrypted volumes and use up-to-date encryption techniques.

Network Security

  • Single Sign On (SSO) and Multi-Factor Authentication (MFA) are enforced.
  • Host Intrusion Detection, virus/malware protection, local and network firewalls, and Access Control Lists are in place.

Third Party Suppliers

  • Third-party suppliers are assessed for their impact on production environments.
  • Security standards are maintained and regularly evaluated for all suppliers.

Additional Information

For more information about OfficeSpace Software’s security, customers can contact their Customer Success Manager or email support@officespacesoftware.com for additional details or reports.