HOSTING
Our servers are hosted on Microsoft Azure, the leading Infrastructure Provider in the world.
SSL ENCRYPTION
All traffic to and from our servers are protected by SSL. SSL (Secure Sockets Layer) is the standard security technology for establishing an encrypted link between a web server and a browser. |
MTSC Certified
Microsoft Azure is Singapore Multi-Tier Cloud Security Standard (MTCS SS 584) Level-3 (CSP) certified together with other global certifications such as the ISO 27001 (Security Management Controls) and ISO 27018 (Personal Data Protection) |
INFRASTRUCTURE
Our IT architecture has been designed to follow the highest security protocol and standards of the market.
PLATFORM SECURITY
We are integrated with a certified IT Cyber Risk Platform that monitors continuously and gives a “MCE Rating” to confirm the level of security. MYCYBEREYES alerts for every application vulnerabilities, data leakage and lack of conformity. They are fixed within 8h00. |
OWASP
Our software is built to systematically consider the OWASP top 10 vulnerabilities. By following these principles, our portal and mobile apps are secured and together with continuous Penetration Testing, it dramatically reduces the risk of a successful cyber attack. |
In-House Security Protocol
My-insurer has designed and follows the strictest set of security mandates and governance to remain in full compliance with the regulatory requirements and guidelines of the governing bodies where it operates.
Data Access & Password Authentication
Data access is governed by strict role-based access controls which is reviewed and audited by independent bodies regularly. Private/Public keys with password protection are required to access to our servers. |
Independent Pen test
My-Insurer performs at least once a year a Pen Test with a Third Party that is mandated to evaluate the overall robustness, scalability and resilience of the platform. It includes but not exhaustive: SQL Flaws, XSS, Malicious File Execution, CSRF, Cryptographic Storage, URL Access. |
Governance, Training & Authorisation
All employees are mandated to attend regular Data Protection and Cyber Security training to ensure security awareness and knowledge of latest security threats. All employees pledged and signed a set of governance policies adhering to the strictest data security and IP confidentiality compliance. |
Multiple Factor Authentication Security Access
All our FA Clients can now activate a 2-factor authentication for even better security !
|
With 2-factor authentication, an extra layer of security is added to your account to prevent someone from logging in, even if they have your password.
|
This extra security measure requires you to verify your identity using a randomized 6-digit code we'll send you each time you attempt to log in to your email address.
|