Abstract digital security visual representing Overpowered's secure development practices

Security

Working with Overpowered isn't just about ROI. It is about partnering with a brand that's fully invested in your security.

We understand that security is paramount in today's digital landscape. Our comprehensive security measures ensure your data and applications are protected at every level.

Servers & Databases: A Safe Haven for Your Data

We use Amazon Web Services (AWS) for our production servers and databases. AWS takes security seriously - almost as seriously as we do. Amazon employs cutting-edge data security measures, as well as physical access restrictions at server locations. We also use Hetzner Online GmbH for additional services to be compliant with the GDPR.

Secure servers and databases

We Care. Now You Know.

SOC Compliance

We don't claim to be SOC compliant, but our datacenter providers are (AWS/Hetzner). Customers interested in SOC reports concerning the cloud infrastructure providers utilized by our services can obtain the reports directly from the respective providers.

PCI Standards

We follow the principles and standard set out by the PCI Standards Council for storing and handling credit card information. More information is available here.

HIPAA Compliance

Customers acknowledge that Overpowered is not a Business Associate or subcontractor (as those terms are defined in HIPAA) and that our Services are not HIPAA compliant.

ISO 27001

We aren't ISO 27001 compliant, but our datacenter provider is (AWS). Customers interested in ISO 27001 report concerning the cloud infrastructure provider utilized by our services can obtain the report directly from the respective provider.

AVAILABILITY

There for You, Always

We understand that you rely on the Overpowered application to improve your website and your business. We're committed to making Overpowered a highly-available application that you can count on. Our infrastructure runs on systems that are fault tolerant for failures of individual servers or even entire data centers. Our operations team tests disaster-recovery measures regularly and staffs an around-the-clock on-call team to quickly resolve unexpected incidents.

High availability infrastructure

Security Features

Disaster Recovery

All of our production infrastructure is built with redundancies in place, in highly-available configurations spread over two different availability zones.

Incident Management

In the event of a security breach, we will promptly notify you of any unauthorized access to your Customer Data. We have incident management policies and procedures in place.

Pen Testing

We engage independent entities to conduct regular application-level and infrastructure-level penetration tests. Results are shared with our Management team and tracked to resolution.

OWASP Security Standards

The OWASP Top-10 covers the most critical Web application security risks. We follow OWASP guidelines and best practices to ensure our applications are secure against the most common vulnerabilities. Our development team is trained on OWASP standards and we regularly audit our code against these guidelines.

OWASP security standards

Bug Bounties

A Proactive Approach

We are interested in actual security, so if someone reports what we feel are both:

  • Serious vulnerabilities (and not just a low/zero-risk XSS)
  • Discovered during routine use of the application as an actual user – not via a pen test

We look kindly on the heads up, and might even send across a thank-you bonus!

PERSONNEL PRACTICES

Our People are Prepared

All employees are required to read and sign our comprehensive information security policy covering the security, availability, and confidentiality of the Overpowered services. We maintain strict access controls and regular security training for all team members.

Security training and personnel practices

Security Policies

IT Security Policy

The objective of this security policy is to promote a culture that helps maximise the value of information through its efficient management and secure protection. It also looks to safeguard Overpowered and the rights of staff and other parties who depend on the information or to whom it relates.

Acceptable Usage Policy

This policy is designed to help our staff understand their responsibilities when utilising, accessing or creating content with Overpowered IT resources or networked services. It clarifies and defines what we deem as an acceptable use of these resources.

Disaster Recovery Policy

Our comprehensive disaster recovery and business continuity policy ensures that your data and services remain available even in the face of unexpected events.

Incident Response Policy

We have detailed incident management and response policies to handle security incidents quickly and effectively, ensuring minimal impact on your business.

LEGAL COMPLIANCE

Secure, From Start to Finish

We employ dedicated legal and compliance professionals with extensive expertise in data privacy and security. These professionals are embedded in the development lifecycle and review products and features for compliance with applicable legal and regulatory requirements. We also have a business code of conduct that makes legal, ethical and socially responsible choices and actions fundamental to our values and standards for meeting those goals.

Legal compliance and security

Ready for your next project ?

Contact Us