At SalesChoice, safeguarding enterprise data, predictive AI models, and user privacy is foundational to everything we build. Our security framework is designed to meet strict industry standards, ensuring your data remains protected, confidential, and highly available across our SalesInsights and MoodInsights platforms.
Our Compliance & Governance Posture
-
SOC 2 Alignment: Built and maintained in accordance with the AICPA SOC 2 Trust Services Criteria (Security, Confidentiality, and Availability).
-
Continuous Monitoring: We utilize Vanta for 24/7 automated control monitoring and compliance verification across our cloud infrastructure, code repositories, and operational workflows.
-
Independent Auditing: Regular internal assessments and third-party penetration testing validate our security defenses against evolving threat vectors.
1. Cloud Infrastructure & Network Defense
SalesChoice is hosted natively within Amazon Web Services (AWS) enterprise data center infrastructure.
-
Virtual Private Cloud (VPC) Isolation: All application workloads operate within isolated VPC environments, partitioned across public, application, and database subnets.
-
Virtual Firewalls & Network ACLs: Access to internal systems is restricted via AWS Security Groups enforcing strict inbound and outbound traffic rules. Direct public internet access to administrative ports (e.g., SSH Port 22) or internal database ports is strictly prohibited.
-
High Availability & Redundancy: Production workloads leverage multi-Availability Zone (AZ) deployments to ensure service resilience and automatic fault tolerance.
2. Data Encryption & Privacy Controls
Encryption Standards
-
Data in Transit: All traffic between user browsers, API endpoints, and SalesChoice infrastructure is encrypted in transit using TLS 1.2 or higher with modern cipher suites. Unencrypted HTTP traffic is automatically upgraded to HTTPS.
-
Data at Rest: All customer databases, data stores, system logs, and cloud storage buckets (AWS S3) are encrypted at rest using industry-standard AES-256 encryption.
Privacy by Design & PII Protection
-
Data Isolation: Customer data is logically segregated within multi-tenant databases to prevent cross-tenant data access.
-
AI Model Security: Customer datasets processed by SalesInsights and MoodInsights are sanitized and anonymized within AI/ML data pipelines to protect Personally Identifiable Information (PII).
-
No Unsanctioned Data Sharing: SalesChoice never sells customer data or shares proprietary client analytics with third parties.
3. Access Control & Identity Management
-
Principle of Least Privilege: System and data access rights are granted strictly on a role-based, need-to-know basis.
-
Multi-Factor Authentication (MFA): MFA is strictly mandated across all corporate, developer, and cloud administrative accounts (Google Workspace, AWS, GitHub, Vanta).
-
Automated Offboarding: Access rights for departing employees or contractors are revoked immediately upon termination in accordance with our Employee Termination Security Policy.
4. Secure Development & Vulnerability Management
-
Secure SDLC: Development workflows adhere to secure Software Development Life Cycle (SDLC) practices designed to mitigate OWASP Top 10 security risks.
-
Peer Reviews & Automated Scanning: All code commits undergo mandatory peer review and automated dependency scanning via GitHub Secret Scanning and vulnerability detection tools before deployment.
-
Penetration Testing: Annual third-party penetration tests are conducted to proactively identify and remediate potential application or infrastructure vulnerabilities.
5. Incident Response & Business Continuity
-
24/7 Security Alerting: Automated CloudWatch and Vanta alerts notify engineering and security leadership immediately upon detecting security anomalies or system health degradations.
-
Incident Response Plan (IRP): Formally documented and annually tested through tabletop simulation drills to ensure rapid triage, containment, eradication, and post-incident reporting.
-
Disaster Recovery (DR): Automated continuous database snapshots and backups are encrypted and stored across secondary locations to guarantee low Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
6. Personnel & Administrative Security
-
Background Checks: All active personnel undergo pre-employment background screening.
-
Confidentiality & NDAs: Employees sign non-disclosure and proprietary information agreements upon onboarding.
-
Security Awareness Training: Mandatory annual security and privacy awareness training is completed by all team members via Vanta.
Dedicated Security & Support Contacts
Have questions about our security practices, or need to report a potential vulnerability?
General Support & Security Inquiries: support@saleschoice.com | help@saleschoice.com
