Security & Reliability

Sharing sensitive information with third parties is a risky but essential part of many business processes. A virtual data room must provide you with the security and privacy functionality required to manage these risks. Knowing that your files will be available at any time 24/7 is also critical - you need to be sure that your entire team can gain access to the content round-the-clock, so choosing a high reliability virtual deal room platform is imperative.
Security and Reliability are at the core of everything we do at Pandesa to develop, deliver and support ShareVault™. This priority is reflected in the functionality of our software, the choice of our data center partner and our own internal security procedures.
Security Functionality
Pandesa ShareVault offers flexible and easy-to-use software features to assure the security and privacy required for your application:
- Data Encryption Pandesa ShareVault uses 128-bit SSL encryption certified by GeoTrust®, helping to ensure that data
transferred to or from Pandesa ShareVault's servers are not susceptible to man-in-the-middle interception.
- Access Control Access permissions can be separately defined for each file, so you have control over who can see what data. ShareVault provides both group-level and user-level access control. ShareVault express provides group-level access control.
- Policy-based Security For each document, you can control which users have the right to access the original file or only the PDF version of the file, and whether the user has the rights to print, save or copy/paste. ShareVault provides unlimited configurable policies. ShareVault express provides three policies, one of which is configurable.
- PDF Security Features Automatically apply a configurable watermark to each page (can include user identification, date and time).
- PDFtrak™ Even after a PDF has been saved (if saving is allowed), the user's rights to open the file can be revoked at any time. Not available with ShareVault express.
- Asymmetric Intra-Group Privacy A remarkably simple privacy mechanism whereby for each user group, the system administrator can configure whether the members of the group are able to view the names of certain other users and user groups.
- Configurable Confidentiality Agreement Users must agree to your confidentiality agreement upon login. A integrated web-based rich text editor allows you to format the agreement to look just the way you want it. ShareVault supports multiple agreements, selectable on a per-user basis, for projects that involve multiple legal jurisdictions. ShareVault express is limited to one confidentiality agreement.
- Strong Authentication Users manage their own passwords, and must choose a strong password. A "forgot password" button right on the log in page allows a user to reset his/her own password using a secure procedure.
Data Center Security & Reliability
Pandesa ShareVault servers are located at a world-class tier-1 data center, managed by an award-winning
high-end provider of managed hosting services. The data centers are SAS-70 type II certified, and offer comprehensive
security and reliability through multiple levels of redundancy:
- High-availability Servers Pandesa ShareVault servers are based on a high-availability configuration, offering redundant, dual hot-swappable
power supplies, network interface cards and RAID hard drives, so that most types of server hardware failures will go unnoticed with no downtime and no loss of data.
- Geographic redundancy Pandesa ShareVault servers are located in two different locations, with automated backups and failover capabilities.
- 24/7 monitoring Servers are monitored by automated support systems that permit real-time analysis, review, and
maintenance. Certified network technicians are on hand around the clock to assure rapid diagnosis and repair
when necessary.
- Redundant network connectivity Our data centers' tier-1 network connectivity provides multiple levels of redundancy.
- Redundant routers Our data centers uses only fully redundant, enterprise-class routing equipment housed in its own secure,
core routing room and fed with its own redundant power supply. Fiber carriers enter the facilities at disparate access
points to ensure that there is no service failure, even in the unlikely event of a fiber cut.
- Backup power Power systems in our data centers are designed to run uninterrupted even in the unlikely event
of a total power outage. All servers are fed with conditioned UPS (Uninterruptible Power Supply) power that will run if
utility power fails. The UPS power subsystem is N+1 redundant with instantaneous failover in case the primary UPS fails.
In the event of an extended power outage, on-site diesel generators can run indefinitely. Generators are regularly tested
to ensure functionality in the event of an emergency.
- Optimized cooling systems Our data centers' HVAC (Heating Ventilation Air Conditioning) systems are N+1
redundant to ensure that - even in the event of an entire HVAC system failure - there is a duplicate system on standby
to take over. All air is circulated and filtered every 90 seconds to remove dust and contaminants.
- Redundant cabling All cables to servers and routing equipment are securely tied down and cable racks suspended from
the ceiling provide dual routes for all cables.
- Physical Security Access to data centers is restricted by two-factor authentication including Biometric hand
scanners. Data centers are physically isolated from everyone but level three technicians. Facilities are un-marked and public access is
strictly forbidden. All entrances and common areas are monitored 24x7 via closed-circuit cameras.
- Fire suppression An advanced fire-suppression system is in place to prevent any fire from spreading - in the
unlikely event that one could start.
- Firewall A server's firewall is the first line of defense against online attacks, which is why our data centers utilize
high end hardware firewalls, and managed monitoring services.
Comprehensive Internal Security Policy and Procedures
Pandesa's commitment to security and reliability does not stop with best-of-breed security technology, but also encompasses best practices for internal policies and procedures, including thorough background checks for all employees, procedures for handling terminated employees, strict policies for managing passwords, and secure procedures for purging customer data when its no longer needed on our servers.