Security and Privacy at Sernova

Security is at the heart of what we do.

Governance

Sernova’s Security and Privacy team establish policies and controls, monitor compliance with those controls and prove our security and compliance to third-party auditors.

Our policies are based on the following foundational principles:

01.

Access should be limited to only those with a legitimate business need and granted based on the principle or least privilege.

02.

Security controls should be implemented and layered according to a principle of defence-in-depth.

Security and Compliance

Sernova maintains a SOC 1 Type II attestation and an ISO 27001 compliance certification. Our SOC 1 Type II report and ISO 27001 certificate are available on our Trust Report.

03.

Security controls should be applied consistently across all areas of the enterprise.

04.

The implementation of controls should be iterative, continuously maturing across the dimensions of improved effectiveness, increased auditability and decreased friction.


Data P
rotection

Product Security

Enterprise Security

Data Privacy

At Sernova, data privacy is a top priority – we strive to be trustworthy stewards of all sensitive data.

Responsible Disclosure