Security is one of the top concerns of enterprise businesses when they are looking to adopt a SaaS solution. A secure SaaS provider requires world-class data centers, stringent identity management and training processes, and rigid security standards.
Comm100 Live Chat is an enterprise-grade live chat application, with security features that perform at the top of the industry. As a SaaS and customer-driven company, we know the true challenges of providing quality and secure live chat services, inside and out.
We have policies and practices that address a whole range of security concerns, building oﬀ of a solid foundation that helps our clients exceed their customers’ expectations.
In this security white paper, we present a detailed and comprehensive report on our security processes and standards. Through this we hope not only to prove our commitment to protecting our customers’ data, but also explain how we keep our application safe from cyber threats.
Comm100 Live Chat allows agents to monitor and engage visitors, as well as obtain crucial information regarding their purchasing and website surﬁng habits. The security measures at the application level help keep this sensitive data guarded from online threats.
1. HTTPS Encryption
When a chat connection is built, all data collected from visitors via multiple forms (i.e. browsers, pre-chat, post chat survey), as well as chat messages transmitted between live chat agents and visitors, is encrypted through HTTPS protocols utilizing the advanced TLS encryption.
2. Credit Card Masking
With the Credit Card Masking feature enabled, credit card numbers that are sent by visitors directly through chat window to agents will be automatically masked and kept private. Instead, you can use the PCI DSS compliant Secure Form to collect sensitive information from visitors during chatting.
3. PCI DSS Compliant Secure Form
Our PCI DSS compliant Secure Form allows you to request sensitive data such as credit card number from visitors through the chat window. This data will not be stored in our database, and agents can only access the data during the chat session. Once the chat session ends, both agents and visitors cannot re-access the data. The Secure Form is certiﬁed for PCI DSS compliance. If your business is PCI DSS compliant and you use our Secure Form to collect credit card holder data during the chats, you will stay compliant without additional audits or expenses.
4. IP Restrictions
You can authorize speciﬁc IPs or IP ranges for your Comm100 Live Chat account. This limits agents to access their accounts from designated IPs. IP restrictions can also be enabled for mobile access.
5. Password Security
Passwords are a crucial and an often-overlooked component of data security – as a result, they can be particularly vulnerable to attacks. Comm100 Live Chat’s password security system contains the following features:
6. Session-Only Cookies
While agents are logged into their live chat accounts, Secure and HttpOnly ﬂags are set in the session-only cookies to ensure account security.
7. Agent Permission Setting
Agents can be assigned customizable permission settings. This limits the actions agents can take as management ﬁnds appropriate.
Permissions can also be granted at department and group levels.
Permission tasks include, but are not limited to:
8. Agent Audit Logs
All agent activities can be tracked through audit logs, providing management with accountability for all actions performed within the application.
You can track information in the audit logs by time period, keyword, and ﬁlter for time-sensitive resolutions. Through permission settings, access to audit logs can be restricted to administration and trusted agents.
A quality live chat application requires the most secure infrastructure possible.
Comm100 Live Chat is committed to only the best, most advanced procedures and policies to keep the foundation of our operations secure.
1. HIPAA Compliance
Comm100 offers HIPAA compliant live chat as a Business Associate under the Health Insurance Portability and Accountability Act of 1996. Our live chat system has been fully assessed to ensure that electronic Personal Health Information (ePHI) is kept secure: All live chat data is fully encrypted, we operate strong firewalls and DDoS protection, and we have additional security measures which ensure that the process of logging into and operating our system is fully compliant.
We comply with the highest levels of infrastructure security to ensure that our live chat is HIPAA compliant. We have undertaken extensive system hardening and network security practices, and operate penetration and vulnerability tests to ensure that we remain compliant. Some of the safeguards and processes we operate to check and maintain compliance include:
2. ISO 27001 Certification
Comm100 has achieved ISO 27001 certification, the international standard which defines best practices within an Information Security Management System (ISMS). Compliance with this standard confirms that Comm100 has compliant governing processes over all hardware, software, people and procedures in accordance with internationally-recognized standards.
3. PCI DSS Compliance
Comm100 Live Chat is PCI DSS compliant as a service provider. PCI DSS (The Payment Card Industry Data Security Standard) is a proprietary information security standard for organizations that handle branded credit cards from the major card companies including Visa, MasterCard, American Express, Discover, and JCB.
Being PCI DSS compliant, we are enforcing the industry leading security controls over the physical environment and all procedures and processes governing our software development, deployment and operation. Our security management is fully repeatable, deﬁned and consistent.
4. Network Security
Beginning with the very ﬁrst point of contact, strong security measures are put in place. All chat requests are validated through a third-party ﬁrewall. This ensures that only legitimate chat requests will be accepted, so that the security of the host website will not be compromised.
5. Server Hardening
All our servers, including chat servers, application servers, and database servers, together with our switches and ﬁrewalls, are hardened complying with relevant standards, including Windows server hardening standards, IIS hardening standards, etc.
6. Anti-Virus Solution
An up-to-date, industry accepted anti-virus solution is critical for successful operations. Comm100 Live Chat has an anti-virus solution that is properly implemented and kept up-to-date. Additionally, all staﬀ members who may have access to the production environment have active and enabled anti-virus on their PCs.
7. Security Patches
Crucial security patches that call for immediate action will be installed within 30 days of patch release. Non-crucial security patches will follow periodic review on a monthly basis, and are applied only after thorough assessment. Additionally, all security patches are immediately installed when setting up a new server.
To ensure top quality, all patching and software updates must pass rigorous testing before a CAB (Change Advisory Board) committee approval.
1. HIPAA Compliance
We operate HIPAA compliant servers in the US. Our disaster recovery processes are also HIPAA compliant, and alongside these we have a full suite of policies designed to ensure HIPAA compliant levels of physical security.
2. ISO 27001 Certification
Comm100 is ISO 27001 certified. The ISO 27001 standard lays out the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented Information Security Management System. It sets a risk-based approach that focuses on adequate and proportionate security controls that protect information assets and give confidence to stakeholders.
3. Data Centers
Comm100 Live Chat is partnered with recognized industry leaders such as Rogers, Peer1 and UK2Group. The data centers were chosen based oﬀ of their commitment to uptime, redundant power sources, and top security features. Our partner data centers pride themselves in:
Our servers are stored separately from others in the data centers to ensure maximum security and privacy. Access to the company’s servers are carefully monitored and recorded for review as necessary.
4. Disaster Recovery
Comm100 Live Chat’s disaster recovery environment ensures continuity for clients, supporting all applications, services and components as they function in the production environment. Every change which passes through the CAB committee review will be performed in both the production and disaster recovery environments.
In the event of a regional disaster disrupting the normal production environment, data backups will be automatically restored to the disaster recovery environment and the service can be up and running in minutes.
Comm100 is ISO 27001 certified, and Comm100 Live Chat is PCI DSS compliant as a service provider. We comply with strict standards regarding processes and procedures in our daily operations
1. HIPAA Compliance
To achieve HIPAA compliance, Comm100 examined all existing policies and procedures relating to application, infrastructure and physical security and updated them to ensure they encompass the full suite of requirements that HIPAA compliance demands. Some of the relevant policies and processes we have in place include:
2. Change Management Measures
Changes at the foundational level are managed under regulated operations detailed in our Change Management Process.
Examples of the changes covered include (but are not limited to):
In addition, we have employed explicit permission management regarding the login authority to our database. Any operation that may harm our database security is strictly prohibited.
3. Internal Development Training
Operational security strategies are only as strong as the team that implements them. Our internal development training covers:
4. Job Role Management
PCI DSS deﬁnes the speciﬁc permissions and duties of diﬀerent roles in a company’s security team. At Comm100, we strictly follow certain standards in our daily security operations.
5. Incident Response
Comm100 Live Chat has a complete incident response plan in place to ensure business continuity. Alarm tools are implemented to identify any potential incident.
Our Information Security Team will be notiﬁed immediately of any suspected or real security incidents involving our computing assets, particularly any critical system or system that handles or processes cardholder or other Personally Identiﬁable Information. Incidents will then be classiﬁed into diﬀerent levels and be taken care of according to speciﬁc procedures.
6. Access Control
Access to our servers and databases is strictly controlled by:
7. 24/7 Service Monitoring
Comm100’s Service Maintenance team monitors the application round the clock, ensuring that potential risks are noticed and acted upon immediately.
As a live chat provider for companies and organizations around the globe, Comm100 Live Chat sets the highest possible standards for how sensitive data is handled. We hope this document serves to inform you about our processes and protocols, as well as about our unwavering commitment to security.