SOC 2 Type II certified
SOC 2 Type II certification is a key part of Outplay's commitment to its existing and future customers - allowing them to be confident about the security of their data.
A compliance program in any industry provides you with goals and standards to work toward. Keeping customers' data secure is a core part of our security and privacy program. Our key certifications and attestations reflect this in how we design our products, the operational security practices we implement, and the layers of protection we provide.
SOC 2 Type II certification is a key part of Outplay's commitment to its existing and future customers - allowing them to be confident about the security of their data.
ISO 27001 is one of the most widely recognized and internationally accepted information security standards. ISO 27001 certification means that we have taken effective steps to protect the confidentiality and the integrity of our current and future customer’s data - keeping their data safe, secure, and accessible.
It increases our resilience to cyberattacks, strengthens our ability to adapt to changes in both the internal and external environment and helps in protecting all forms of data - cloud, digital, or hard copy.
EU citizens' personal information and their privacy are protected under the GDPR as a condition of conducting business within EU member states. The compliance of Outplay with these regulations was assessed by a third party.
Traffic on our systems is encrypted over SSL/HTTPS. Internal firewalls and access lists are in place to isolate our network.
An integrated log management system streams logs in real-time over secure channels. We collect everything from application logs to AWS Cloud Trail logs for a complete audit trail of employee and user activity without compromising production systems. We also provide technical support and development teams with access to logs without gaining access to production systems.
We keep our systems updated with the latest deployments and patches. Every change to the database is logged. Our systems are periodically backed up and tested.
Also as our primary Infrastructure as a Service (IaaS) provider, Outplay hosts its production infrastructure on Amazon Web Services.
To help keep our applications safe and secure, we also perform periodic penetration testing with third-party vendors. These tests are conducted in-depth on the areas of network, server, database.
We allow access only to key members of Outplay’s team. Password sharing is highly forbidden.
Our distributed server architecture ensures that even if one system goes down, the rest of the environment stays secure. Database instances are separated from application servers.
The status of Outplay’s portal is available publicly. Outplay’s dev-ops team also monitors the uptime continuously.