Where is Client Data physically and logically hosted?
All data is stored on AWS in the us-east-2 region.
Is our data stored and processed exclusively within the United States, or does any portion of it reside with, or get transferred to, servers or personnel outside the U.S.?
All data is stored exclusively within the United States, aside from our EU customers.
Who has access to our data? Crystal Tech personnel directly, or any third-party subprocessors/vendors? If subprocessors are involved, could you identify them and their role?
No data is shared with any third party vendors without the written consent of the retailer. With this approval, API access can be given to vendors such as BIG and a variety or e-commerce providers we work with.
What encryption standards are applied to our data both at rest and in transit?
For performance reasons, we do not currently encrypt data at rest. However, we never store any payment information, and have initiatives to encrypt all PII data.
What are your data backup, retention, and disaster recovery practices for our account?
We store 30-day rolling backups on all our servers. Upon request, we can provide additional one-time backups, however these may be subject to additional fees.
Is our Client Data stored in a shared/multi-tenant database or environment alongside other Crystal Tech clients’ data, or is it logically or physically segregated? If another client of yours experienced a breach, would our data be exposed to any additional risk as a result of how the environment is architected?
Client data is stored in a completely separate database, therefore if there was a breach on our main production environment, no client data would be accessible.
Does Crystal Tech currently hold any third-party security certifications or attestations (e.g., SOC 2, ISO 27001), and if so, which ones?
Crystal does not currently hold SOC 2 or ISO 27001 certificates, however we are working on the initial process of obtaining SOC 2.