WorkBuzz Security
With WorkBuzz, you’re in safe hands. We use enterprise grade best practices to provide a secure, reliable and resilient cloud-based platform, which protects our customers.
With WorkBuzz, you’re in safe hands. We use enterprise grade best practices to provide a secure, reliable and resilient cloud-based platform, which protects our customers.
Hundreds of thousands of employees around the globe use the WorkBuzz platform to securely provide feedback and suggestions to their company. Our clients have a wide variety of security and privacy needs, with many coming from the most highly regulated and security-sensitive industries in the world. With this in mind, security is of the utmost importance to our platform and vision
ISO 27001 is the de facto international standard for information security management. WorkBuzz has been ISO 27001 certified by the British Assessment Bureau and annually renews the certification through an ongoing auditing process. The most recent certificate can be found here.
You can verify the validity of our ISO certificate by entering our certificate number 231455 via this link: certcheck.ukas.com
We have designed a system meant to minimise any service disruptions resulting from natural disasters, hardware failure, or other unforeseen disasters or catastrophes, with all data regularly backed up.
All employees are trained on WorkBuzz’s information security processes and procedures as part of their onboarding. This is reviewed and redelivered annually to ensure that employees are up to date with the latest security risks.
Our developers have regular security training to stay informed of our common and emerging security risks in the development, as well as the data privacy of our customers’ data.
All employees and contractors agree to comply with defined security policies, which include confidentiality, data privacy, and incident reporting.
WorkBuzz has designed a system meant to minimise any service disruptions resulting from natural disasters, hardware failure, or other unforeseen disasters or catastrophes.
Our Disaster Recovery approach includes:
In addition, we employ Multi-Availability Zones (Multi-AZ) within the AWS cloud hosting environment. This ensures that all production data is replicated in a physically distinct data centre in real-time. In the event of total failure of the primary data centre, the WorkBuzz application can be resurrected (without loss of data) using the Multi-AZ facility.
We understand that hosting locations are important. WorkBuzz platforms and websites are hosted by Amazon Web Services (AWS) in London and Dublin. AWS facilities are compliant with ISO27001.
We have put in place measures to prevent your data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those of our people and other third parties who have a business need to know. They will only process your personal data on our instructions and where they have agreed to treat the information confidentially and to keep it secure. We have put in place procedures to deal with any suspected data security breach and will notify you and the ICO of a suspected breach where we are legally required to do so.
Confidentiality terms come standard in all WorkBuzz agreements with our customers. In addition, all employees are required to sign confidentiality agreements with WorkBuzz that protect customer data. WorkBuzz also has confidentiality terms with all vendors that handle personal or confidential information of our customers as part of our vendor review process (see below).
Any data requested from Clients is password protected to ensure data is encrypted during transit. Clients using the WorkBuzz platform are able to upload data directly into the system meaning no transfer to/from individuals is required. When client data is processed outside secure WorkBuzz systems, it shall be encrypted in transit. Encryption in transit may include encrypting a file sent via email, encrypting a portable hard disk being used to transfer data or through the use of encrypted transmission protocols such as TLS.
We encrypt user passwords by using best practice to minimise the impact of a data breach. Almost all of our services use encryption at the best industry best practice symmetric encryption schemes. All WorkBuzz owned devices have a full disk encryption setup and are enabled by default using Microsoft BitLocker.
WorkBuzz’s testing and staging systems are separated logically from production systems. For testing, WorkBuzz facilitates dedicated test data.
WorkBuzz contracts with a third-party penetration tester to perform independent penetration tests at least annually. Our security engineers are continuously testing new and existing features regarding vulnerabilities to increase the security level of our application via AWS Inspector.
A summary for the most recent penetration test is available on request under a Non-Disclosure Agreement.
With its roots in the United Kingdom, WorkBuzz has put privacy and data protection at the core of how we have developed our products, services, and our internal governance.
EU General Data Protection Regulation (GDPR)
WorkBuzz complies with the requirements of the EU General Data Protection Regulation and provides a secure communication platform that protects employee and client data equally. The privacy rights of our clients, and their employees, and the security of their personal data are our highest priorities.