Secure Software Development Lifecycle establishedFormal SSDLC with security requirements, threat modelling and design review for every new feature.
Change management procedures enforcedAll changes authorised, documented, tested in pre-production, reviewed and approved before production, with separation between authorising and implementing changes.
Mandatory peer code reviewEvery pull request is scanned for vulnerabilities and requires senior developer approval.
Static and dynamic application security testingSAST and DAST run automatically in CI/CD on every code change.
Software composition analysisThird-party and open-source dependencies scanned for vulnerabilities and licensing on every change.
Secrets and container image scanningSecrets scanning and container image scanning built into the CI/CD pipeline.
Critical and High vulnerabilities blocked from productionThe CI/CD pipeline prevents Critical and High findings from being released.
Annual third-party penetration testingIndependent application penetration test following OWASP WSTG and PTES methodologies.
Secure coding trainingOWASP Top 10 training for developers at onboarding and annually.
Access Control
Role Based Access Control (RBAC) establishedAccess granted on least-privilege and need-to-know principles.
Multi-factor authentication enforcedOkta SSO with non-bypassable MFA (push notification or passkey) across in-scope systems.
Quarterly user access reviewsUser permissions and privileged access are reviewed every quarter.
Privileged access approval workflowPrivileged access requires approval and is granted only through change management or just-in-time workflows.
Just-in-time, time-bounded production accessAdministrative access to production is brokered through AWS Systems Manager Session Manager with MFA and time-limited permissions.
Privileged sessions recordedPrivileged production sessions are recorded in full.
Privileged account sharing prohibited
Timely access revocation on offboarding
Encryption
AES-256 encryption at restApplied across DocumentDB, S3, EBS, Kubernetes secrets and backups.
TLS 1.3 in transitTLS 1.2 minimum, with Perfect Forward Secrecy and HSTS on all internet-facing hosts.
Mutual TLS between internal services
Encryption key management process establishedAWS KMS keys rotated annually, audit-logged and never exposed in plaintext.
Application secrets stored in AWS Secrets ManagerAccess to Secrets Manager is separately audited.
Data Security
Secret values are never storedHush stores only metadata about secrets and non-human identities: type, location, name and exposure context.
Strict tenant isolationEnforced through tenant-specific identifiers and access controls, validated by annual penetration testing.
No production data in non-production environmentsDevelopment, staging and production are fully separated across distinct VPCs and AWS accounts.
Data retention and secure deletion policyCustomer data is deleted within 30 days of contract termination, with early deletion available on request.
Data loss preventionSensitive data transmission over email is monitored and restricted; extracting customer data from production is prohibited by policy.
Network Security
Network segmentation into security zonesMulti-tier design separating public-facing components, application logic and data storage.
Databases in private subnetsDatabase services have no direct internet access.
Least-privilege network access rulesAWS Security Groups, NACLs and firewall rules allow only the required ports and protocols.
WAF and DDoS protectionAWS WAF with the OWASP Core Rule Set and rate limiting on all external services.
Continuous threat detectionAmazon GuardDuty with alerting on unauthorised access attempts.
Firewall rules monitored and reviewedOngoing monitoring by DevOps and an annual ruleset review.
Quarterly external vulnerability scans
Infrastructure
Hosted on AWS across multiple Availability ZonesProduction runs in us-east-1, built to the AWS Well-Architected Framework.
Infrastructure as CodeDeployed with Terraform onto Kubernetes through automated CI/CD with rollback capability.
Hardening aligned to CIS benchmarksDocumented Baseline Security Configuration Policy for operating systems, containers and applications.
Container base images rebuilt at least monthlyAutomated rebuilds are triggered when new vulnerabilities are detected.
Patch management SLAsCritical patches within 24 hours, High within 7 days, Medium within 30 days.
Centralised, tamper-resistant loggingAudit logs shipped to Coralogix outside the production estate, alongside CloudTrail and CloudWatch, protected by encryption, access controls and immutability.
Endpoint Security
Endpoint Detection and Response deployedSentinelOne EDR with behavioural and anomaly-based detection on all employee endpoints.
Mobile Device Management enforcedAll endpoints centrally managed through JumpCloud MDM.
Full-disk encryption enforced
Threat and malware protection enforced
Removable media and unauthorised peripherals blocked
Software installation restricted to approved applicationsInstalled software is reviewed quarterly by senior management.
Endpoints never connect directly to production
Corporate Security
Information Security Policy reviewed annually
Annual risk assessment and treatment
Asset management maintained
Code of conduct acknowledged by all personnel
Background screening performed
Security awareness and data privacy training
Board oversight of security and operations
Cyber liability insurance maintained
Incident Response
Incident Response Policy and program establishedDefined severity levels, roles, escalation procedures and communication protocols.
Customer notification within 24 hoursFor any incident that impacts, or is reasonably suspected to impact, customer data, security or service availability.
24/7 security alerting to on-callAlerts from CloudTrail, GuardDuty, Coralogix, Okta and EDR are routed immediately for triage.
Root cause analysis for high-severity incidentsPrepared and reviewed by management.
Incident response procedures tested
Business Continuity
Business Continuity and Disaster Recovery plans established
Disaster recovery tested annuallyDrills include cyberattack-driven outage scenarios.
Automated encrypted backupsDaily backups replicated across three Availability Zones with cross-region replication, immutability and integrity checks.
Backup restoration tested annually
Availability
99.5% availability SLA
Recovery Time Objective of 12 hours
Recovery Point Objective of up to 24 hours
Multi-AZ production architecture
Privacy
Data Protection Officer function establishedPrivacy is overseen by the Hush Legal team, acting as Data Protection Officer.
Compliance with GDPR, CCPA and the Israel Privacy Protection Law
Data subject rights supportedRequests for access, correction, deletion and objection, including the right to object to automated decision-making, are handled.
Data minimizationHush collects only the metadata needed to operate the platform; secret values are never stored.
Defined retention and secure deletionCustomer data is deleted within 30 days of contract termination, or earlier on request.
Vendor Management
Vendor risk assessment before onboarding
Ongoing monitoring of subservice organizationsManagement oversight confirms subservice organizations continue to operate in a controlled manner.
Contractual security and confidentiality terms with third parties