@cryptotaxi247 / netdata-1 / commits / e5eca7a24

Update README.md

Costa Tsaousis committed Mar 22, 2024 at 17:25 UTC e5eca7a24d3a463def758a6e6e2af8d82f1e14f4
1 file changed +34
docs/security-and-privacy-design/README.md
+34
@@ -211,6 +211,40 @@ Business Associate Agreement (BAA), it is ultimately the responsibility of the h
211 compliance across all of their operations. Entities should always consult with a legal expert or a HIPAA compliance
212 consultant to ensure that their use of any product, including Netdata, aligns with HIPAA regulations.
213
214 +## SOC 2 Compliance and Netdata
215 +
216 +### Understanding SOC 2 Compliance
217 +
218 +Service Organization Control 2 (SOC 2) is a framework for managing data to ensure the security, availability, processing integrity, confidentiality, and privacy of customer data. Developed by the American Institute of CPAs (AICPA), SOC 2 is specifically designed for service providers storing customer data in the cloud. It requires companies to establish and follow strict information security policies and procedures.
219 +
220 +### Netdata's Alignment with SOC 2 Principles
221 +
222 +While Netdata is not currently SOC 2 certified, our commitment to security and privacy aligns closely with the principles of SOC 2. Here’s how Netdata's practices resonate with the key components of SOC 2 compliance:
223 +
224 +### Security
225 +
226 +Netdata has implemented robust security measures, including infrastructure as code, TLS termination, DDoS protection, and a security-focused development process. These measures echo the SOC 2 principle of ensuring the security of customer data against unauthorized access and potential threats.
227 +
228 +### Availability
229 +
230 +Netdata's commitment to system monitoring and troubleshooting ensures the availability of our service, consistent with the availability principle of SOC 2. Our infrastructure is designed to be resilient and reliable, providing users with continuous access to our services.
231 +
232 +### Processing Integrity
233 +
234 +Although Netdata primarily focuses on system monitoring and does not typically process customer data in a way that alters it, our commitment to accurate, timely, and valid delivery of services aligns with the processing integrity principle of SOC 2.
235 +
236 +### Confidentiality
237 +
238 +Netdata's measures to protect data—such as data encryption, strict access controls, and data isolation—demonstrate our commitment to confidentiality, ensuring that customer data is accessed only by authorized personnel and for authorized reasons.
239 +
240 +### Privacy
241 +
242 +Aligning with the privacy principle of SOC 2, Netdata adheres to GDPR and CCPA regulations, ensuring the protection and proper handling of personal data. Our privacy policies and practices are transparent, giving users control over their data.
243 +
244 +### Continuous Improvement and Future Considerations
245 +
246 +Netdata is committed to continuous improvement in security and privacy. While we are not currently SOC 2 certified, we understand the importance of this framework and are continuously evaluating our processes and controls against industry best practices. As Netdata grows and evolves, we remain open to pursuing SOC 2 certification or other similar standards to further demonstrate our dedication to data security and privacy.
247 +
248 ## Conclusion
249
250 In conclusion, Netdata Cloud's commitment to data security and user privacy is paramount. From the careful design of the