Reference
Security Overview
This section gives details on our data access policies, security measurements, and provides a high-level overview of components used in our infrastructure. This overview mostly refers to the Software-as-a-Service version of Rencore Governance; for more information on self-hosting, please refer to the self-hosting documentation.
Information Security Policy
Where can I find a copy of your Information Security Policy?
- Rencore’s Information Security Policy (also referred to as the Acceptable Use and Information Security Policy) is available for download from Rencore’s Trust Center, after signing an NDA
- Security overview from Rencore’s compliance system: https://url.rencore.com/securityreport.
- An up-to-date SOC 2 Type 2 report for Rencore Governance, and Rencore’s ISO 27001/ISO 27017 certificate, are also available from Rencore’s Trust Center.
Where can I find a copy of your Master Service Agreement or SLA?
- SaaS Agreement: https://url.rencore.com/governance-tos.
- Data Processing Agreement: https://url.rencore.com/governance-dpa.
Roles and Responsibilities
Who at Rencore can access data and systems at Rencore?
Only senior qualified staff have access to our production cloud environments and subscriptions based on zero trust concepts.
What level of access do subcontractors or third-party partners have to Rencore’s cloud systems?
No access: subcontractors and third-party partners do not have access to any production or cloud environments.
Infrastructure
How do customers connect securely to Rencore Governance?
The web portal interface is always enforced over TLS 1.3 (https). Any communication with data storage happens from the web portal’s backend.
How does Rencore secure the infrastructure and the services in Azure?
The Rencore Platform is hosted in a separate Azure subscription. Nobody has access to this subscription except for the Product Operations team, which has access to the cloud infrastructure. No access to customer data or encryption keys is allowed to anyone at Rencore unless granted in accordance with the System Access Control Policy.
All resources in the Rencore Platform infrastructure are deployed into a specific Virtual Network, where firewalls are enabled by default across all services. Requests are automatically denied unless the requests come from a service within the virtual network. Our CI/CD platform is allowed to deploy updates to the infrastructure as part of normal operations, which requires access to the administrative interface of Microsoft Azure; this access is granted just in time for the update procedure to be completed and it is automatically removed right after it. Other than this process, no external requests are allowed, even if they were authenticated. Only our Web Application Firewall allows external requests from the direction of the internet.
Processing data from a customer tenant (connecting to, downloading, and analyzing data), happens from inside Azure Container Instances. Every ACI is deployed to our Virtual Network and is uniquely deployed for each customer and each job. We delete each container when the analysis has finished, and therefore, we can never reuse containers.
Does Rencore’s infrastructure adhere to any particular compliance standards?
Rencore Governance has a SOC 2 Type 2 report, which is can be downloaded from Rencore’s Trust Center after signing an NDA. The same applies for materials pertaining to Rencore’s ISO 27001/ISO 27017 certification.
Rencore adheres to its catalogue of security and other internal policies: a broad overview of this can be obtained from https://url.rencore.com/securityreport.
Application
If Rencore’s system or application is web-based and connects to a database, what measures have been taken to mitigate SQL injection?
In line with Rencore’s Secure Development Lifecycle Policy, a number of good practice security measures are in place, including using parameters to sanitize the user input and the use of source code security scans to identify potential issues before they have any chance to be deployed into production.
Has Rencore tested the system or application against OWASP Top 10 issues and other security vulnerabilities?
Rencore uses a number of measures to help secure Rencore Governance, including good security practices embedded into software development lifecycle, external security testing and internal scanning that includes code scanning and running of OWASP ZAP (Zed Application Proxy) attacks against the solution, ensuring none of the OWASP vulnerabilities are present.
Access Control
Please describe how Rencore Governance manages tenant access and authorization to the solution.
Rencore Governance uses multitenant Entra ID applications to grant the Rencore Platform access to the data required to perform analysis and monitoring.
Customers can at any point revoke the App-Only or Delegated permissions granted to our applications.
Secure Development and Change Management
Does Rencore utilize any form of SDL (Security Development Lifecycle) in its code development framework?
Rencore has a fully developed software development lifecycle that embeds security into this framework. Rencore makes use of vulnerability scanners and security analyzers on the codebase, one of which is Veracode. However, the underlying principle of our development process is that everyone should be alert regarding security - we ask everyone involved in all stages of the development lifecycle to ask themselves the following questions, among others:
- What are the risks?
- How could something go wrong here?
- What would the impact be if something goes wrong?
- How are we going to secure this?
- Is this the right thing to do?
- Are we in compliance with GDPR and other relevant privacy laws?
- Can we do this with fewer administrative privileges?
- Is this data-sensitive?
- Are we encrypting the data properly?
Everyone involved in product development is required to ask questions, assess risks, and do the right thing at every step during the lifecycle of our software.
Please explain how Rencore handles defects and describe the process for bug handling.
Bugs, requests for improvements and changes are reported by customers to our support team. They classify and escalate accordingly to the Product team for verification, implementation, and roll-out. This process is consistent with Rencore’s Vulnerability Management Policy.
In Rencore’s Quality Assurance Testing, do you make use of automated and manual testing?
We have a growing set of automated functional UI, unit and integration tests and we also perform stringent manual testing of all features and bug fixes.
In Rencore’s Quality Assurance Testing, do you verify the performance aspects of the application?
Yes. We run automated functional UI tests, and we perform performance tests to understand where there may be bottlenecks. We also investigate the performance recommendations of the services running in Azure.
Our Content Scanning service is limited by the hosted services we analyze (Microsoft 365). The performance of the analysis is therefore always limited to that of the Microsoft online services’ throttling restrictions.
In your Quality Assurance Testing, do you check for security vulnerabilities?
We utilize the OWASP ZAP tools to execute OWASP Top 10 attacks against the application to check for vulnerabilities. We are also guided by the general principle that security is everyone’s concern.
Data Privacy
Where can I find additional data privacy information for Rencore Governance?
- Rencore’s privacy notice, with regard to instances in which Rencore is acting as a data controller: https://url.rencore.com/privacy-policy
- A Data Processing Agreement can be concluded, or in some cases is automatically incorporated, on signing a contract for Rencore Governance
Please provide information on where or at which datacenter customer data will reside.
Data is stored in Azure Storage Accounts in one of the available datacenters that are specified during the configuration of a Workspace.
If your system or application contains sensitive data at rest, does the system encrypt this data, and how?
Yes. All information is encrypted.
Azure Storage Accounts and PostgreSQL have built-in support for encryption at rest and in transit.
If your system is designed to process, store, or transmit privacy data, is it compliant with the EU General Data Protection Regulation?
Yes. We are GDPR compliant and take all the measures required to maintain such compliance on a continual basis.
How do you ensure GDPR compliance with regard to the stored customer data?
We store URLs, titles, and other metadata of the collected data, like Site Collections, Sites, Lists, Teams, etc. The collected customer data can be removed at any time by removing the encrypted storage tables belonging to the customer.
Any PII (personally identifiable information) is also encrypted.
Customers can make a request to our support to have all their data deleted, subject to a 30-day retention period for the deletion of Workspaces, to protect them against accidental deletion, and subject to a longer retention period for some historic non-personal data. Data in backups may be stored for up to 60 days, due to how Rencore’s backup processes function and due to the archival period to protect data from accidental deletion.
When a customer terminates its business arrangements with you, how long after the termination do you hold or keep customer data before it is completely purged?
Customers can delete their accounts in the Rencore Governance portal which immediately (within a maximum of 10 minutes) puts the data into purge mode. This data can be restored by sending a request to Rencore support; after 30 days the data is permanently deleted.
What data leaves the client, and when?
Depending on the configured inventories and policies in Rencore Governance, during the scan of a Microsoft 365 tenant, we collect instance information about site collections and child elements (sites, lists, files, customizations), Teams teams, M365 groups, etc. This data is validated by our compliance policy engine and we store information about violated policies in our backend.
Is data leaving the client in an encrypted state?
Yes. We utilize all the built-in capabilities of encryption in transit (TLS 1.3) and encryption at rest (Azure Storage and PostgreSQL encryption).
How do you make sure that third parties, including Rencore, cannot access data leaving the customer?
Limited staff at Rencore have access to our cloud environments in production, as determined by the System Access Control Policy. Full audit logging and alerts are enabled for all administrators. All data stored in the Rencore platform is encrypted and protected behind firewalls in Azure.
Availability
Do you have any SLAs regarding availability?
Yes, we guarantee 99.5% availability.
Is the application limited to use in certain regions?
We allow requests from all regions to our applications, but the Rencore Governance service is only offered to countries where the global Microsoft 365 service is available.
Technical Overview
This section describes, at a high-level, which Azure cloud components we utilize, and which components and technology the solution is built upon.
Cloud Components
Which components of the Azure Cloud do you use?
The Rencore Platform service relies on the modern cloud capabilities of Microsoft’s public cloud, Azure.
Virtual Networks
- We use multiple dedicated subnets inside a single Virtual Network in each region to maintain subnet level separation, also because Azure requires subnet segregation per resource or resource types.
Managed Identity
- We use User Assigned Managed Identity to grant the Functions and Web Apps access to resources like the Azure Key Vault.
Azure Storage Accounts
- Stores the system data required for operating the solution.
- Saves the customer data, as is necessary to provide accurate reports.
- The firewall is enabled and only allows traffic through the dedicated subnets. No external traffic is permitted.
PostgreSQL
- Stores the system data required for operating the solution.
- Saves the customer data, as is necessary to provide accurate reports.
- The firewall is enabled and only allows traffic through the dedicated subnets. No external traffic is permitted.
Azure App Services
- Azure Function Apps
- Web Apps
Azure Key Vault
- Secrets and sensitive data are stored here.
- The firewall is enabled and allows traffic through the dedicated subnets. No external traffic is permitted.
- Rencore’s CI/CD platform can deliver updates using short-lived, temporary Just-In-Time network connections.
Azure Container Instances
- Isolated Docker containers, per customer, without externally reachable endpoints or ports.
- Used to retrieve data securely from customer tenants and process in the solution, fully isolated on a per-analysis, per-customer basis. We delete containers after each analysis.
- Resides in the protected virtual network, in the container subnet.
Azure Application Insights
- We send telemetry and diagnostics to an Application Insights instance, enabling us to monitor the solution’s health.
Solution technology
Can you describe the macroscopic solution architecture at a high level?
The solution uses a supported version of .NET (Core not Framework) with a delay of a couple of months after a new major version is released by Microsoft.
Rencore Platform design looks like this, at a high level:
- Docker containers: Built on the supported version of .NET base images from Microsoft.
- Web Application: Built on the supported version of Blazor, for ASP.NET.
- Function Apps: Built on the latest supported version of .NET.
- PostgreSQL and Storage Accounts: To contain data to run the product.
How do you handle data security in the solution?
We make use of the built-in security mechanisms of Microsoft and their industry-standard data protection layers in-transit and at rest; we regularly verify the security of Microsoft Azure by reviewing Microsoft’s relevant certifications and accreditations.
- At REST: We use all the built-in encryption mechanisms of Microsoft Azure. These use AES 256-bit industry-standard encryption algorithms.
- In TRANSIT: We use TLS 1.3 for all communication, and before being sent, we encrypt all data using the additional AES 256-bit industry-standard encryption algorithms.