Copy-paste ready answers for your security questionnaires
Yes. We maintain an information security program with documented policies, procedures, and controls aligned with SOC 2 Type II framework principles. This includes regular risk assessments, security training, and continuous monitoring.
Yes. A dedicated security function oversees the information security program, including policy development, incident response, and compliance monitoring.
Yes. Security policies are reviewed at least annually and updated as needed based on risk assessments, regulatory changes, and industry best practices.
Email/password authentication with multi-factor authentication (MFA) support. SSO/SAML integration available for enterprise customers. Password complexity and session timeout policies enforced.
Granular RBAC with platform-level and tenant-level roles. Principle of least privilege enforced. Permissions are reviewed regularly and adjusted based on job function changes.
Privileged access is restricted to authorized personnel only. Administrative actions are logged. Periodic access reviews are conducted to ensure appropriate access levels.
User access is provisioned based on approved requests. De-provisioning occurs immediately upon termination or role change. Automated processes ensure timely removal of access rights.
Data at rest: AES-256 encryption. Data in transit: TLS 1.2 or higher. Encryption keys are managed using industry-standard key management practices with appropriate rotation policies.
Logical separation at application and database layers. Tenant identifiers validated on every request. Cross-tenant data access prevented through access control policies and query filters.
Customer data is hosted on enterprise-grade cloud infrastructure with geographic redundancy. Specific regions are documented in service agreements and can be configured based on customer requirements.
No. Customer data is not used for AI training, marketing analytics, or shared with third parties without explicit customer consent. Data is processed solely for service delivery purposes.
Yes. Development team receives security training including OWASP Top 10, secure coding practices, and threat modeling. Training is refreshed annually.
Code review, automated security scanning, dependency vulnerability checks, and functional testing. Critical changes undergo additional review by senior engineers.
Continuous dependency monitoring with automated alerts for known vulnerabilities. Security patches prioritized based on severity and exploitability. Critical patches expedited.
Yes. Security researchers and customers can report vulnerabilities to our security team. Reports are triaged and remediated based on severity.
User authentication events, administrative actions, data access, configuration changes, failed login attempts, and security-relevant system events. Logs include timestamp, actor, action, and affected resources.
Minimum 90 days with extended retention available for compliance requirements. Audit logs are immutable and tamper-evident.
Yes. Automated alerting for security events including unauthorized access attempts, configuration changes, and system anomalies. Security team receives and triages alerts 24/7.
Yes. Customers can access audit logs relevant to their tenant through the platform's audit interface or via export functionality.
Automated daily backups with point-in-time recovery. Backups encrypted and stored in geographically separate locations. Backup integrity verified through periodic restore tests.
Target RTO: <4 hours. Target RPO: <24 hours. Actual performance may vary based on incident scope and complexity. Recovery procedures are documented and tested.
Yes. Disaster recovery procedures are tested periodically. Results inform updates to recovery playbooks and infrastructure improvements.
Target availability is documented in service level agreements. System status and incident history are available to customers through status pages.
Customers retain full ownership of their data. We act as a data processor on behalf of customers (data controllers) per applicable data protection regulations.
Yes. DPAs, Business Associate Agreements (BAAs), and Standard Contractual Clauses (SCCs) are available based on customer requirements. Contact your account team.
Only data necessary for service delivery is collected. Configurable retention policies allow customers to define data lifecycle. Data deletion requests honored per contractual terms.
Customers can export their data directly through the platform. We provide assistance with DSARs as required by applicable data protection laws.
Current subprocessor list is available at /security/subprocessors. All subprocessors are vetted for security and data protection practices.
Third-party risk assessments conducted prior to engagement. Data processing agreements in place with all subprocessors. Periodic reviews ensure ongoing compliance.
Yes. Customers are notified of material changes to subprocessor lists per contractual terms. Objection mechanisms are provided where applicable.
We are responsible for security OF the platform (infrastructure, application, access controls). Customers are responsible for security IN the platform (user access management, data classification, appropriate use).
Strong password practices, enabling MFA, timely user de-provisioning, regular access reviews, appropriate data classification, and adherence to acceptable use policies.
Contact us for tailored security documentation and questionnaire assistance
VentaHR Support
We're here to help
Welcome to VentaHR Support. Need help with onboarding, login, or applications?
Select a Topic
Direct email: support@ventahr.com
Mon–Fri, 9am–5pm EST