Security Measures
This Annex forms part of the DPA.
Ghost is committed to developing secure, reliable products utilising all modern security
best practices and processes.
The Ghost security team is made up of full time staff employed by the Ghost Foundation
as well as volunteer open source contributors and security experts. We do both
consultation and penetration testing of our software and infrastructure with external
security researchers and agencies.
We take security very seriously at Ghost and welcome any peer review of our
completely open source codebase to help ensure that it remains completely secure.
Administrative security measures
VENDOR ASSESSMENTS
- Ghost Foundation has vendor selection processes in place to assess vendors for suitability, including in relation to how vendors handle personal data. Amongst other things, Ghost Foundation ensures that it has legally binding arrangements with vendors to ensure that personal data disclosed to vendors is protected to the same standards that Ghost Foundation itself offers, and in compliance with all applicable personal data protection laws.
EXTERNAL USER ACCESS CONTROLS
- Users are required to log in to user accounts before accessing non-public services and data.
- Customers can define various user access levels to manage access and use of non-public services and data.
INTERNAL USER ACCESS CONTROLS
- All Ghost Foundation employees are required to log in to user accounts before accessing non-public customer services and customer data.
- Ghost Foundation defines various user access levels to manage access and use of non-public customer services and customer data by its employees and vendors.
Physical security measures