bilabl commits to delivering the highest level of security, reliability, privacy, and compliance in our products and services. Here are measures bilabl takes to keep your data secure.
BILABL is a native SaaS solution, built on state-of-the art infrastructure. We embed security best practices into everystep of our development lifecycle.
Here’s an outline of our architecture:
● Cloud provider: Amazon Web Services (AWS)
● Infrastructure as code tool: Terraform
● Source code management: Git, Gitlab
● CI/CD: Gitlab CI/CD
● Container orchestration: Kubernetes (EKS)
● DBMS: Postgres (AWS RDS)
● Search Engine: Elasticsearch
● Logging & Monitoring: Datadog
● Programming Language: Golang, Python, React
● Architecture: Microservices
BILABL utilises industry-leading Amazon Web Services (AWS) to provide you with a secure, fast, reliable, and infinitely expandable cloud platform. The infrastructure is designed and managed inalignment with best security practices and a variety of IT security standards. The following is a partial list of assurance programs with which AWS complies:
● SOC 1/ISAE 3402, SOC 2, SOC 3
● FISMA, DIACAP, and FedRAMP
● ISO 9001, ISO 27001, ISO 27017,ISO 27018
BILABL encrypts data both at-rest and in-transit using 256-bit AES encryption for SSL/TLS web traffic and 2048 bit RSA public keys. We use a combination of application based encryption and hosting solutions to align with industry best practices, ensuring that it can’t be accessed by unauthorised parties.
BILABL follows industry best practices for SaaS Authentication. User’s password is encrypted and filters in our log files. Our servers log every access attempt with full details (i.e. userID, IPaddress, date/time, result), and are monitored for failures. Repeated authentication failures are automatically blocked.
For higher protection, all accounts are able to enforce the use of strong passwords and Multi-Factor Authentication(MFA) through Microsoft Authenticator or your Office365 account.
BILABL does backup automatically on a daily, weekly and monthly basis to Amazon's S3 service. You always retain ownership of your data and can request a full export of your database and files at any time.
BILABL is prepared to respond to any incident. We have a standard process to address the incident at hand and communicate effectively. As our Service Level Agreement (SLA), we commit the availability, maintenance, and response and recovery times of the software.
BILABL’s API is supported by industry-standard OAuth 2.0, access restricted by OAuth 2.0 scopes and governed by BILABL terms of services. All integrations must be directly authorised and signed at the User-level offering visibility and control.