OmaxTelecom

Security, privacy, and reliability information for eSIM and white-label, SMS and SMPP, API, and voice services. For documentation or questions, contact our security team directly.

Safeguards

Controls

How we design and operate security across our platform and services.

  • 36 controls
  • By security area

Status icons indicate a control described on this page. They are not an independent audit or certification.

Infrastructure security

ControlStatus
  • Database replication utilized

    The company's databases are replicated to a secondary data center in real-time. Alerts are configured to notify administrators if replication fails.

    Published statement
  • Production data backups conducted

    The company performs periodic backups for production data. Data is backed up to a different location than the production system.

    Published statement
  • Unique production database authentication enforced

    The company requires authentication to production datastores to use authorized secure authentication mechanisms, such as unique SSH keys.

    Published statement
  • Encryption key access restricted

    The company restricts privileged access to encryption keys to authorized users with a business need.

    Published statement
  • Unique account authentication enforced

    The company requires authentication to systems and applications to use unique usernames and passwords.

    Published statement
  • Production data segmented

    The company prohibits confidential or sensitive customer data, by policy, from being used or stored in non-production systems or environments.

    Published statement
  • Production application access restricted

    System access is restricted to authorized access only.

    Published statement
  • Access control procedures established

    The company's access control policy documents the requirements for adding new users, modifying users, and removing an existing user's access.

    Published statement
  • Production database access restricted

    The company restricts privileged access to databases to authorized users with a business need.

    Published statement
  • Firewall access restricted

    The company restricts privileged access to the firewall to authorized users with a business need.

    Published statement
  • Production OS access restricted

    The company restricts privileged access to the operating system to authorized users with a business need.

    Published statement
  • Production network access restricted

    The company restricts privileged access to the production network to authorized users with a business need.

    Published statement
  • Access revoked upon termination

    The company completes termination checklists to ensure that access is revoked for terminated employees within SLAs.

    Published statement
  • Unique network system authentication enforced

    The company requires authentication to the production network to use unique usernames and passwords or authorized Secure Shell (SSH) keys.

    Published statement
  • Remote access MFA enforced

    The company's production systems can only be remotely accessed by authorized employees possessing a valid multi-factor authentication (MFA) method.

    Published statement
  • Remote access encryption enforced

    The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection.

    Published statement
  • Log management utilized

    The company utilizes a log management tool to identify events that may have a potential impact on the company's ability to achieve its security objectives.

    Published statement
  • Infrastructure performance monitored

    An infrastructure monitoring tool is utilized to monitor systems, infrastructure, and performance and generates alerts when specific predefined thresholds are met.

    Published statement
  • Network segmentation implemented

    The company's network is segmented to prevent unauthorized access to customer data.

    Published statement
  • Network firewalls reviewed

    The company reviews its firewall rulesets at least annually. Required changes are tracked to completion.

    Published statement
  • Network firewalls utilized

    The company uses firewalls and configures them to prevent unauthorized access.

    Published statement
  • Network and system hardening standards maintained

    The company's network and system hardening standards are documented, based on industry best practices, and reviewed at least annually.

    Published statement
  • Service infrastructure maintained

    The company has infrastructure supporting the service patched as part of routine maintenance and as a result of identified vulnerabilities to help ensure that servers supporting the service are hardened against security threats.

    Published statement

Organizational security

ControlStatus
  • Asset disposal procedures utilized

    The company has electronic media containing confidential information purged or destroyed in accordance with best practices, and certificates of destruction are issued for each device destroyed.

    Published statement
  • Production inventory maintained

    The company maintains a formal inventory of production system assets.

    Published statement
  • Portable media encrypted

    The company encrypts portable and removable media devices when used.

    Published statement
  • Anti-malware technology utilized

    The company deploys anti-malware technology to environments commonly susceptible to malicious attacks and configures this to be updated routinely, logged, and installed on all relevant systems.

    Published statement
  • Employee background checks performed

    The company performs background checks on new employees.

    Published statement
  • Code of Conduct acknowledged by employees and enforced

    The company requires employees to acknowledge a code of conduct at the time of hire. Employees who violate the code of conduct are subject to disciplinary actions in accordance with a disciplinary policy.

    Published statement
  • Confidentiality Agreement acknowledged by contractors

    The company requires contractors to sign a confidentiality agreement at the time of engagement.

    Published statement
  • Confidentiality Agreement acknowledged by employees

    The company requires employees to sign a confidentiality agreement during onboarding.

    Published statement
  • Performance evaluations conducted

    Company managers are required to complete performance evaluations for direct reports at least annually.

    Published statement
  • Password policy enforced

    The company requires passwords for in-scope system components to be configured according to the company's policy.

    Published statement

Data and privacy

ControlStatus
  • Data retention procedures established

    The company has formal retention and disposal procedures in place to guide the secure retention and disposal of company and customer data.

    Published statement
  • Customer data deleted upon leaving

    The company purges or removes customer data containing confidential information from the application environment, in accordance with best practices, when customers leave the service.

    Published statement
  • Data classification policy established

    The company has a data classification policy in place to help ensure that confidential data is properly secured and restricted to authorized personnel.

    Published statement

Questions about a control? Email security@omaxtelecom.com.