Security Statement

 

Overview

Keeping our clients’ data secure is Audiense’s #1 priority. We take a multi-layered approach to information security known as “Defense in Depth.” Defense in Depth is a strategy that incorporates enterprise data protection best practices to ensure our clients’ data remains secure while in our environment. We ensure client data is treated with the utmost care from the time we receive it until the time it is securely deleted.

We embrace and enforce a philosophy of least privilege throughout our ecosystem to ensure information is accessible only to authorized personnel with a legitimate business need. Audiense will never resell information provided by clients to any third party.

As you continue to learn more about Audiense, we recommend you also review our Privacy Policy.

Compliance and Certifications

SOC 2 Type II and HITRUST Compliance

SOC 2 Type II and HITRUST reports are independent third-party examination reports that help clients understand Audiense’s control environment.

Audiense has completed a System and Organization Controls (SOC) 2 Type II examination and maintains HITRUST certification. HITRUST is based on a rigorous set of information security requirements tailored to the protection of Protected Health Information (PHI) and other confidential data. The HITRUST framework incorporates controls from more than 40 authoritative security frameworks and standards, including HIPAA, NIST, CIS, FedRAMP, GDPR, and ISO 27001.

Audiense has taken significant steps to create, document, implement, and monitor processes required to maintain a high level of data security and confidentiality. These examinations cover critical factors including:

  • Risk management
  • System operations
  • Change management
  • Data monitoring
  • Confidentiality controls
  • Security governance

The purpose of these examinations is to demonstrate that Audiense’s controls are suitably designed and operate effectively to ensure the security of its systems and the confidentiality of client data.

Audiense applies the same strict security controls to all client data regardless of whether it contains personally identifiable information (PII).

Security Governance

Security Team

Our infrastructure and security teams maintain AWS and Information Security certifications. Our Executive Security Committee (ESC) includes senior leadership from Finance, Technology, Information Security, Systems Engineering, and Corporate Operations.

Security is enforced from the highest levels of the organization and remains one of Audiense’s top priorities.

Infrastructure Security

Cloud Hosting

The Audiense platform is hosted on Amazon Web Services (AWS) cloud infrastructure within the United States. Audiense currently utilizes AWS data centers located in Virginia and California.

By leveraging AWS, Audiense benefits from industry-leading physical and logical security controls, highly available infrastructure, network segmentation, continuous monitoring, and regularly updated systems and firewalls.

Additional information regarding AWS security practices is available at:

https://aws.amazon.com/security/

Subservice Organizations

Audiense utilizes certain third-party service providers to support platform operations, including:

  • Amazon Web Services (AWS) – cloud hosting and infrastructure services
  • Google – mapping and geocoding services
  • Microsoft DevOps – software development lifecycle support
  • Okta – identity and authentication services
  • Salesforce – customer relationship management services
  • Recurly – subscription billing and payment processing

Data Security

Data Storage

All client data is stored within the United States.

Client data is housed within dedicated environments designed to prevent unauthorized access and cross-contamination between clients. As data progresses through production systems, it may be transformed, summarized, de-identified, and stored using Audiense-managed encryption controls.

Data retention policies are implemented to ensure data is retained only as long as necessary to fulfill contractual and operational obligations. Upon request, original client data may be securely destroyed and a certificate of destruction can be provided.

Data Transfer

Data ingestion and client deliverables are transferred using secure managed file transfer processes and approved APIs.

Security controls include:

  • Transparent Data Encryption (TDE) for databases
  • SSL/TLS encryption for data in transit
  • SMB3 encryption for approved Windows system transfers
  • 256-bit endpoint disk encryption
  • Data Loss Prevention (DLP) technologies
  • Security Information and Event Management (SIEM) monitoring
  • Restrictions on removable USB storage devices
  • Controls preventing mobile devices from connecting directly to production environments

Authentication and Access Control

Password Security

User passwords are protected using industry-standard cryptographic hashing and key derivation functions. Audiense enforces password complexity requirements and encourages users to implement strong password practices.

Multi-Factor Authentication

Audiense is served entirely over HTTPS and all external traffic is encrypted in transit.

Multi-factor authentication (MFA) is utilized for:

  • Client platform access
  • Internal systems access
  • Administrative functions

Strong password policies are enforced across all systems.

Permissions and Administrative Controls

Audiense enables permission levels to be configured for individual users. Access may be restricted based on:

  • Specific datasets
  • Functional responsibilities
  • Administrative privileges
  • Business requirements

Access is granted according to the principle of least privilege.

Secure Development Practices

Security is integrated throughout the software development lifecycle.

Every source code change must successfully pass through:

  • Testing
  • Quality control review
  • Quality assurance review
  • Security validation procedures

Reviews are designed to identify:

  • Malicious code
  • Backdoors
  • Unauthorized functionality
  • Logic flaws
  • Security vulnerabilities

Audiense follows the OWASP Application Security Verification Standard (ASVS) as a framework for evaluating and implementing application security controls. OWASP ASVS provides comprehensive requirements and testing standards that support secure software development.

Monitoring and Auditing

Application Monitoring

Audiense utilizes multiple monitoring solutions to oversee the health and performance of:

  • Databases
  • Distributed processing systems
  • Load balancers
  • Web servers
  • Supporting infrastructure

User access to the platform is logged and reviewed as necessary.

Changes within the platform are logged and tracked through formal Enterprise Change Management processes.

Security Audits

Audiense regularly engages independent third-party auditors to review security controls and validate their effectiveness.

In addition, Audiense continuously evaluates emerging threats and implements new controls where appropriate to maintain a strong security posture.

Vulnerability Management

Protecting customer data is a continuous process.

Security issues may be identified through:

  • Vulnerability scanning
  • Internal reviews
  • Security assessments
  • Vendor notifications
  • Industry security publications
  • Routine operational activities

When a security threat is identified, Audiense follows a structured process:

  1. Understand the nature of the threat.
  2. Assess the likelihood and potential impact.
  3. Determine remediation or mitigation requirements.
  4. Prioritize corrective actions based on risk.
  5. Validate successful remediation.

Incident Response

Incident Response Program

Audiense maintains formal incident response procedures and regularly trains employees on security policies and responsibilities.

If a security event is detected:

  1. The event is reviewed by designated security personnel.
  2. Escalation occurs to the Executive Security Committee when warranted.
  3. The Incident Response Team is assembled if further investigation is required.
  4. Appropriate remediation actions are implemented.

Following resolution, a post-incident review is conducted to identify lessons learned and opportunities for improvement.

Service Availability

Audiense maintains a target uptime of 99% or higher.

Platform architecture is designed with:

  • High availability
  • Scalability
  • Disaster recovery capabilities
  • Immutable backup strategies

These controls help ensure resilience against operational disruptions and cyber threats.

Payment Security

Audiense does not store customer debit or credit card information.

Payment processing is performed by Recurly, a PCI-DSS Level 1 compliant payment processor, representing the highest level of payment card industry certification.

Payment information is transmitted directly to Recurly through encrypted channels and is not stored within Audiense systems.

Additional information regarding Recurly security practices is available at:

https://recurly.com/security/

Reporting Security Concerns

If you suspect a security vulnerability, suspicious activity, or security incident involving the Audiense platform, please contact us immediately.

Security Contact Email: help@audiense.com

Chief Information Security Officer: CISO@buxtonco.com

Phone: (817) 332-3681

All reported security concerns are investigated and addressed according to established security procedures.

Customer Responsibilities

Audiense’s controls are designed with the assumption that customers maintain appropriate controls within their own environments.

Customers are responsible for:

  • Granting access only to authorized personnel.
  • Protecting their own systems and infrastructure.
  • Ensuring data transmissions are authorized and accurate.
  • Maintaining disaster recovery and business continuity plans.
  • Monitoring activity within their own networks.
  • Notifying Audiense of relevant security incidents.
  • Maintaining accurate technical and administrative contact information.

Contact Information

Phone: (817) 332-3681

Security Reporting: CISO@Audiense.com

Request a Free Trial