Since this is a multi-tenant architecture, how do I make sure my applications and processes on Pervasive DataCloud2 are not accessed by others?
- Each Pervasive DataCloud tenant has their own set of credentials. Users need both a private and a public key to access their private Pervasive DataCloud2 processes.
- Pervasive does not share any keys outside our API, so there is no shared public storage.
- Entities cannot be deleted. However, customers can control their metadata.
What security protocol does Pervasive DataCloud use?
The DataCloud uses the Secure Sockets Layer (SSL) protocol with AES 128-bit or 256-bit encryption protocol for the TLS connection.
How do you address security during process execution?
From an execution standpoint, your process will never run on the same virtual machine as another data services process (i.e., each instance is separate from another). The machine operating on your behalf does not let you access it unless the Pervasive API lets you in with your secure credentials. If data does not belong to a particular process, a user of that process is not allowed access to the data. The user/product hierarchy does not let a user cross over to other products or processes.
Is PGP 'At-Rest' Encryption available?
PGP Encryption is available for all data that Pervasive DataCloud2 handles “at rest” (i.e., persisted on disk) during operations. We do database-level encryption of user settings for configurations and parameters. All user metadata is encrypted using AES 128-bit encryption prior to storage, and the encrypted password is stored in the keystore, which in turn is isolated from the database.
How do you provide support for sensitive data?
Pervasive DataCloud enables PGP libraries are enabled in the Amazon instances to allow the Pervasive engine to decrypt and encrypt at-rest data. Encrypted keys can be stored in your Pervasive DataCloud repository or anywhere else on the Internet, and downloaded and used at runtime to encrypt and decrypt files.
How does Pervasive interact with Amazon Web Services' S3 storage?
The DataCloud controls access to S3 storage through the Pervasive DataCloud API security structure.
Please describe the security of Amazon Web Services (AWS).
The AWS firewall is 'locked down," meaning security is high and your virtual environment will be safe. Other Amazon machines cannot affect yours, and AWS restricts access of non Pervasive systems.
Is Pervasive DataCloud2 on a SAS 70 Type 2 audited infrastructure?
Yes. The Pervasive DataCloud is hosted on Amazon Web Services (AWS), a SAS 70 Type 2-audited site. In November 2009, AWS successfully completed a Statement on Auditing Standards No. 70 (SAS70) Type II Audit, and has obtained a favorable unbiased opinion from independent auditors. SAS 70 certifies that a service organization has had an in-depth audit of its controls (including control objectives and control activities), which in the case of AWS relates to operational performance and security to safeguard customer data.
Is Pervasive DataCloud PCI compliant?
The Pervasive DataCloud2 undergoes routine third-party site scans to meet the requirements of the PCI Security Standards Council. We invite you to review our site scan results.