Security Statement

Security Statement

Secure Personnel

Confidentiality or Non-Disclosure Agreements (NDAs) are signed by all employees and contractors, who have a need to access sensitive or internal information. Security training and testing are conducted for Metricus employees and contractors.

Metricus support team accesses application data only for purposes of application health monitoring and performing system or application maintenance, and upon customer request for support purposes. Only authorized Metricus employees have access to application data.

Secure Software Development

All software development projects follow secure development lifecycle principles. All development undergo design review to ensure security requirements are incorporated. All software development team members undergo regular secure development training. Software development is conducted in line with OWASP Top 10 recommendations for web application security.

Secure Testing

Metricus deploys third-party penetration testing and vulnerability scanning of all production and Internet-facing systems on a regular basis.

We perform static and dynamic software application security testing of all code, including open-source libraries, as part of our software development process.

Cloud Security

Metricus Cloud provides maximum security with complete customer isolation in a modern, multi-tenant cloud architecture. Metricus Cloud is hosted on the Microsoft Azure (East US data center in Richmond, Virginia and North Europe data center in Dublin).

  • Each Metricus account imported data are stored in a separate database schema and are isolated from other customer data. Each incoming web request is authenticated and authorized before access to customer data is allowed.

  • All data is encrypted at rest and in transmission to prevent any unauthorized access and prevent data breaches.

  • Metricus application database full backups are performed once per day and are retained for 10 days. All backup data are encrypted. Backups are stored in the Azure Cloud Platform.