Our Commitments
Security and Privacy at Empowerly:
Learn more about Empowerly’s security and privacy commitments.
Empowerly conducts annual business continuity and security incident exercises and audits to follow recommended best security practices.
Penetration Testing and Vulnerability scanning
Penetration testing is important to help organizations proactively identify and fix security vulnerabilities before attackers can exploit them. Empowerly is committed to annual penetration testing to prevent data breaches and unauthorized access to confidential information.
Internal code reviews are performed using a PR-based development workflow and are audited by a vulnerability scanner. Security vulnerabilities directly affecting Empowerly’s systems and services will be patched or otherwise remediated within a timeframe appropriate for the severity of the vulnerability, subject to the public availability of a patch or other remediation mechanisms.
Protection of Empowerly Endpoints
All Empowerly-distributed devices are under centralized management and equipped with both mobile device management (MDM) tools, encryption, and anti-malware protection. Endpoint security is actively monitored, and through MDM, we ensure devices follow strict security policies, including enforced disk encryption, automatic screen locks, and up-to-date software.
Evaluation of Vendor Risk and Security
Empowerly uses factors such as access to customer and employee data, integration with customer-facing environments, and potential damage to Empowerly to calculate the risk rating of each vendor. We carefully evaluate the security of each vendor to arrive at a residual risk rating per vendor.
Education of Company Security Best Practices
Empowerly understands the importance of preemptively establishing and practicing security best practices to protect both its customers and the company. Both employees and contractors are mandated to complete annual security training.
SOC 2
Empowerly is SOC 2 Type 2 Compliant. Please reach out to us at security@empowerly.com to request access to the report.
