Security OverviewWe provide this overview so that you can better understand the security measures we’ve put in place to protect the information that you store using UberSimple’s AppPack (“AppPack”).
Secure StorageWe encrypt the files that you store on AppPack using the AES-256 standard, which is the same encryption standard used by banks to secure customer data. Encryption for storage is applied after files are uploaded, and we manage the encryption keys. AppPack uses Amazon S3 for data storage. Amazon stores data over several large-scale data centers. According to Amazon, they use military grade perimeter control berms, video surveillance, and professional security staff to keep their data centers physically secure. You can find more information about Amazon's security at the Amazon Web Services' website. Amazon and AppPack also employ significant protection against network security issues such as Distributed Denial of Service (DDoS) attacks, Man in the Middle (MITM) attacks, and packet sniffing.
Secure TransfersYour files are sent between AppPack’s mobile apps and our servers over a secure channel using 256-bit SSL encryption where supported.
Your Data is Backed UpUberSimple and Amazon keep redundant backups of all data over multiple locations to prevent the remote possibility of data loss. In the unlikely event that this redundancy were to fail, AppPack data linked to a computer client will still contain copies of your data (except data you’ve chosen not to sync using Remove option).
PrivacyA copy of our full privacy policy can be found at: https://www.AppPack.me/privacy. We guard your privacy to the best of our ability and work hard to protect your information from unauthorized access. UberSimple employees are prohibited from viewing the content of files you store in your AppPack account, and are only permitted to view file metadata (e.g., file names and locations). Like most online services, we have a small number of employees who must be able to access user data for the reasons stated in our privacy policy (e.g., when legally required to do so). But that’s the rare exception, not the rule. We have strict policy and technical access controls that prohibit employee access except in these rare circumstances. In addition, we employ a number of physical and electronic security measures to protect user information from unauthorized access.
Third-party AppsIf you choose to access AppPack using third-party applications (“apps”), be aware that those apps utilize their own security protocols and have their own privacy policies. If you’re not comfortable with the privacy and security features of those apps, you shouldn’t use them to access AppPack. For example, third-party apps might not employ encryption when transmitting data, might collect information that AppPack does not, and might use information differently than AppPack does.
Compliance with Laws and Law EnforcementAs set forth in our privacy policy, and in compliance with United States law, AppPack cooperates with United States law enforcement when it receives valid legal process, which may require AppPack to provide the contents of your private AppPack. In these cases, AppPack will remove AppPack’s encryption from the files before providing them to law enforcement.
How to Add Your Own Layer of Encryption to AppPackUberSimpleapplies encryption to your files after they have been uploaded, and we manage the encryption keys. Users who wish to manage their own encryption keys can apply encryption before placing links to files in their AppPack. Please note that if you encrypt files before linking to them, some features will not be available, such as public viewing. Doing so will also make it impossible for us to recover your data if you lose your encryption key.
I think I've found a security exploit. Where do I report security concerns?We take a number of measures to ensure that the data you store on AppPack is safe and secure. While we're very confident in our technology, we recognize that no system can guarantee data security with 100% certainty. For that reason, we will continue to innovate to make sure that our security measures are state of the art, and we will investigate any and all reported security issues concerning AppPack's services or software. For a direct line to our security experts, report security issues to security@AppPack.me. We'll fully credit anybody whose reports lead to the improvement of AppPack security. A list of those who have contributed reports leading to a bug or security issue can be found on our special thanks page. |
|