Security Practices

Last Updated: June 8, 2026  ·  Equet.com

Protecting customer data is one of our most important responsibilities. We're committed to being transparent about our security practices and helping you understand our approach. Highlights of our security program are provided below.

Equet operates in alignment with SOC 2 compliance standards and conducts regular reviews with external auditors.

Security Governance

Our Security Governance Team (SGT) is a governing body consisting of cross-functional management representatives led by the Chief Information Security Officer (CISO). The SGT meets on a regular basis to advise, prioritize, and enable the Information Security Program.

The risk-driven Information Security Program includes administrative, technical, and physical safeguards to align with applicable requirements, standards, and best practices. We maintain information security policies that are regularly reviewed, updated, and approved on a predefined schedule.

We conduct industry-standard security risk assessments periodically to identify, analyze, monitor, and respond to risk. Our multi-faceted approach includes vulnerability assessments, penetration testing, and other forms of security reviews. Risk treatments are strategically planned and prioritized with key stakeholders to ensure alignment with security and business objectives.

People Security

Employee Background Checks

Before onboarding new staff, we perform reference checks. Where local labor law or statutory regulations permit, we may also conduct criminal, credit, immigration, and security checks. The extent of these background checks is dependent on the position and country.

Security Training For All Employees

All employees and contractors undergo security training as part of the orientation process and receive ongoing security training throughout their tenure. During orientation, new employees must read and agree to our Acceptable Use Policy (AUP) and Code of Conduct, which highlights our commitment to keep customer information safe and secure.

Operational Security

Access Management

For Equet employees, access rights and levels are based on their job function and role, using the concepts of least-privilege and need-to-know to match access privileges to defined responsibilities. All personnel are required to use multi-factor authentication and strong passwords. Access to production infrastructure is strictly controlled using two-factor authentication. Privileged access to both corporate and production resources is subject to a review process, and manual recertification is performed, at a minimum, on a quarterly basis.

Vulnerability Management

We administer a vulnerability management process that involves periodic third-party scans for security threats using a combination of commercially available tools, intensive automated and manual penetration efforts, quality assurance processes, software security reviews and external audits. Once a vulnerability requiring remediation has been identified, it is logged, prioritized according to severity, and assigned an owner.

Malware Prevention

We take threats to our networks and customers very seriously and use a variety of methods to prevent, detect and eradicate malware. We leverage Anti Malware solutions on all corporate laptops and servers. A Safe Link service is used to check links before users click on them, to prevent malware from being installed through infected websites.

Monitoring and Alerting

Equet invests heavily in the automation of monitoring, alerting and response capabilities so that potential issues are continually addressed. Engineers and administrators are alerted to anomaly occurrences, particularly application attacks, error rates, and abuse scenarios. Automatic responses and alerts to appropriate teams are triggered by these and other anomalies so that investigation and correction can occur.

Data Center Security

Equet primarily uses Microsoft Azure, Google Cloud Platform (GCP), and Amazon Web Services (AWS) in the USA for cloud infrastructure. We do not move customer data between cloud regions outside of the USA. The physical security of cloud infrastructure data centers features a layered security model, including safeguards like custom-designed electronic access cards, alarms, vehicle access barriers, perimeter fencing, metal detectors, biometrics, and intrusion detection.

Encrypting Data In Transit and At Rest

Equet customer data is encrypted when it's on a disk using AES-256bit encryption. Data in transit over the Internet or traveling between data centers is encrypted using TLS 1.2 or higher. Only standardized encryption protocols and algorithms are used. Database passwords are stored securely using a one-way hash.

Recovery and Highly Available Solution

Equet designs the components of our platform to be highly redundant. Customer data is replicated synchronously in real time over multiple geographically distributed data centers to minimize the effects of regional disruptions such as natural disasters and local outages. In the event of hardware, software, or network failure, automatic failover allows customers to continue working in most cases without interruption.

Data Security

Data Segregation

Customer data is logically separated using RBAC in our databases or isolated databases depending on customer needs. We maintain separate production, staging and development environments.

Employee Access To Customer Data

We apply the principle of least privilege in all operations to ensure confidentiality and integrity of customer data. All access to systems and customer data within the production network is limited to those employees with a specific business need.

Audit Trails

All actions taken to make changes to the infrastructure or to authenticate directly to production systems are logged for auditing purposes. Only authorized team members have direct access to production servers and databases.

Employee Authentication

Every Equet employee is provided with a list of approved secure password managers that can be used to generate, store, and enter unique and complex passwords. All access to the production servers and data is protected using network isolation and strong authentication mechanisms. A combination of strong passwords and two-factor authentication (with number matching) is used to shield mission critical systems.

Data Retention & Destruction

Data retention policies are in place for disposal of customer NPI and PII data within 90 days of a request by a current or former customer or in accordance with Customer's agreement(s).

Application Security

Secure Software Development Lifecycle

Standard best practices are used throughout our software development cycle from design to implementation, testing, and deployment. All code is checked into a permanent version-controlled repository. Code changes are always subject to peer review and continuous integration testing to screen for potential security issues.

Secure By Design

All features are reviewed by a team of senior engineers as soon as they are conceived. We plan all functionalities with security in mind to protect the platform against security threats and privacy abuses. We leverage modern browser protections to prevent Cross-Site Scripting (XSS), Clickjacking and other code injection attacks.

Security Testing

Once features are implemented, we perform internal security testing to verify correctness and resilience against attacks. We follow the leading Open Web Application Security Project (OWASP) Testing Guide methodology for our security testing efforts. In addition, we regularly engage top-tier third-party security companies to independently verify our applications.

Release Management

Our products are constantly optimized through a modern and continuous delivery approach to software development. For SaaS products, seamless updates can be deployed without downtime associated with the releases.

Network Security

Network and Application Firewalls are in place allowing only explicitly authorized ingress traffic. Threat Detection Systems are in place to detect and block anomalous traffic patterns and malicious actions against the environment.

Third Party Vendor Management

We rely on several third-party vendors to deliver our service. Prior to onboarding third-party suppliers, Equet conducts an assessment of the security and privacy practices of third-party suppliers to ensure they provide a level of security and privacy appropriate to their access to data and the scope of the services they are engaged to provide.

Regulatory Compliance & Privacy

Equet customers have varying regulatory compliance needs. Our clients operate across regulated industries. Our SGT team continuously monitors and responds to changes.

SOC 2 compliance adheres to standards set by the American Institute of Certified Public Accountants (AICPA) for service organizations, which is also known as SSAE 18.

Customer data privacy is a primary consideration at Equet. As discussed in our Privacy Policy, personal data is never sold to third parties. Customer needs and privacy considerations guide the design and building of Equet's platform and services.

For further inquiries regarding our security policy, please contact us at [email protected].