CASA has built upon the industry-recognized standards of the OWASP's Application Security Verification Standard (ASVS) to provide a consistent set of requirements to harden security for any application. Further, CASA provides a uniform way to perform trusted assurance assessments of these requirements when such assessments are required for applications with potential access to sensitive data.
SAML Single Sign-on (SSO) allows you to authenticate users in your own systems without requiring them to enter additional login credentials. For password-based authentication, you can turn on two-factor authentication (2FA).
We enable permission levels within the app to be set for your teammates. Permissions can include app settings, billing, user data, or the ability to read or send messages.
We maintain an uptime of 99.9% or higher. You can check our past month stats at our status page.
HelpWave services and data are hosted in Amazon Web Services (AWS) facilities in Oregon (us-west-2).
HelpWave was built with disaster recovery in mind. All infrastructure and data are spread across three AWS availability zones and will continue to work should any one of those data centers fail.
All our servers are within our own virtual private cloud (VPC) with network access control lists (ACLs) that prevent unauthorized requests from reaching our internal network.
On an application level, we produce audit logs for all activity, ship logs to ELK and Cloudwatch for analysis, and use S3 for archival purposes.
Access to customer data is limited to authorized employees who require it for their job. HelpWave is served 100% over HTTPS. We run a zero-trust corporate network with no additional privileges from being on HelpWave’s network.
Our API and application endpoints are TLS/SSL only and score an “A+” rating on Qualys SSL Labs’ tests. Data at rest is encrypted using the industry-standard AES-256 encryption algorithm.
HelpWave uses third-party security tools to continuously scan for vulnerabilities. Annually, we engage third-party security experts to perform detailed penetration tests on our application and infrastructure.
HelpWave implements a protocol for handling security events, including escalation procedures, rapid mitigation, and post-mortem analysis. All employees are informed of our policies.