1.अवलोकन और दायरा
यह Security Exhibit ग्राहक डेटा को unauthorized access, disclosure, alteration, और destruction से सुरक्षित रखने के लिए डिज़ाइन किए गए BambooHR's technical and organisational security measures ("Security Measures") का वर्णन करता है। यह Exhibit सम्मिलित है और BambooHR Data Processing Agreement का भाग बनता है।
BambooHR को SOC 2 Type II framework (AICPA Trust Services Criteria for Security, Availability, and Confidentiality) के अंतर्गत प्रमाणित किया गया है और इन नियंत्रणों के design तथा operating effectiveness की पुष्टि करने के लिए वार्षिक तीसरे पक्ष के audits से गुजरता है। ग्राहक NDA के अधीन BambooHR's most recent SOC 2 report की प्रति हमारी security team से हमारे contact page के माध्यम से संपर्क करके अनुरोध कर सकते हैं।
2.इन्फ्रास्ट्रक्चर और नेटवर्क सुरक्षा
BambooHR's का production infrastructure United States में Amazon Web Services (AWS) पर hosted है, और redundancy के लिए डेटा को अनेक availability zones में replicated किया जाता है। सभी production systems एक Virtual Private Cloud (VPC) में strict network access controls के साथ isolated हैं। BambooHR unauthorized access और सामान्य web-based attacks से सुरक्षा के लिए firewalls, intrusion detection systems, और web application firewalls का उपयोग करता है।
BambooHR नेटवर्क सुरक्षा के लिए defence-in-depth approach अपनाता है, जिसमें production, staging, और development environments के बीच network segmentation; infrastructure components की automated vulnerability scanning; और anomalous activity के लिए network traffic की continuous monitoring शामिल है।
3.डेटा सुरक्षा और एन्क्रिप्शन
सभी Customer Data TLS 1.2 या उच्चतर का उपयोग करके transit में encrypted है। rest पर सभी Customer Data AES-256 encryption का उपयोग करके encrypted है। Database encryption keys को सख्त access controls और rotation policies के साथ AWS Key Management Service (KMS) के माध्यम से managed किया जाता है।
Customer Data application-level और database-level controls के माध्यम से अन्य ग्राहकों के डेटा से logically segregated है। BambooHR विभिन्न डेटा श्रेणियों के लिए उपयुक्त security controls की पहचान और लागू करने हेतु नियमित data classification exercises करता है।
4.एप्लिकेशन सुरक्षा
BambooHR एक secure software development lifecycle (SSDLC) का पालन करता है जिसमें security requirements definition, threat modelling, security vulnerabilities के लिए code review, और security testing शामिल हैं। सभी code changes deployment से पहले कम से कम एक engineer द्वारा reviewed किए जाते हैं, और changes automated security scanning के अधीन होते हैं।
BambooHR एक स्वतंत्र तृतीय-पक्ष security firm द्वारा किए गए annual penetration testing का संचालन करता है। Critical और high-severity findings को निर्धारित SLAs के भीतर remediate किया जाता है। BambooHR एक vulnerability disclosure programme भी संचालित करता है जो बाहरी researchers को संभावित security issues रिपोर्ट करने की अनुमति देता है।
5.पहुंच नियंत्रण और प्रमाणीकरण
production systems तक पहुँच केवल authorised BambooHR personnel को need-to-know, least-privilege basis पर सीमित है। production environments तक सभी पहुँच के लिए multi-factor authentication (MFA) आवश्यक है और उसे logged तथा audited किया जाता है। Privileged access की quarterly समीक्षा की जाती है और employee termination पर तुरंत revoked कर दिया जाता है।
ग्राहक multi-factor authentication, single sign-on (SSO), और role-based access controls (RBAC) को अपने BambooHR खातों में configure कर सकते हैं। BambooHR Okta, Azure AD, और Google Workspace सहित प्रमुख identity providers के साथ SAML 2.0-based SSO integration का समर्थन करता है।
6.घटना पहचान और प्रतिक्रिया
BambooHR एक documented Security Incident Response Plan बनाए रखता है, जो security incidents का पता लगाने, वर्गीकरण, containment, investigation, और recovery के लिए प्रक्रियाएँ परिभाषित करता है। incident response team में security, engineering, legal, और customer support functions के प्रतिनिधि शामिल हैं।
BambooHR संभावित security incidents का पता लगाने के लिए automated alerting और 24/7 on-call security monitoring के संयोजन का उपयोग करता है। Customer Data को प्रभावित करने वाली security incident की पुष्टि होने पर, BambooHR लागू कानून और Data Processing Agreement के अनुसार प्रभावित customers को seventy-two (72) hours के भीतर सूचित करेगा।
7.व्यावसायिक निरंतरता और आपदा पुनर्प्राप्ति
BambooHR एक Business Continuity Plan (BCP) और Disaster Recovery Plan (DRP) बनाए रखता है, जिनका परीक्षण कम-से-कम वार्षिक रूप से किया जाता है। BambooHR अपने core platform services के लिए चार (4) घंटे का Recovery Time Objective (RTO) और एक (1) घंटे का Recovery Point Objective (RPO) निर्धारित करता है।
Customer Data को point-in-time recovery के साथ निरंतर backup किया जाता है और daily snapshots तीस (30) दिनों तक retained रहते हैं। Backup integrity का नियमित परीक्षण किया जाता है ताकि यह सुनिश्चित हो सके कि डेटा को recovery scenario में सफलतापूर्वक restored किया जा सकता है।
8.कर्मचारी सुरक्षा और प्रशिक्षण
production systems या Customer Data तक पहुँच रखने वाले सभी BambooHR employees employment से पहले background checks से गुजरते हैं और confidentiality agreements पर हस्ताक्षर करते हैं। सभी employees नियुक्ति के समय तथा उसके बाद प्रतिवर्ष अनिवार्य security awareness training पूरी करते हैं, जिसमें phishing awareness, password hygiene, और data handling responsibilities जैसे विषय शामिल हैं।
BambooHR के पास employees और contractors के लिए एक documented acceptable use policy है जो personal activities और unauthorized data access के लिए BambooHR systems के उपयोग को निषिद्ध करती है। उल्लंघनों पर termination सहित disciplinary action की जा सकती है।








































