Arrow

Jopari is committed to providing you with a secure infrastructure that is compliant with state and federal security regulations to protect your information. Jopari used an independent auditor that has verified that our security practices and contractual commitments comply with state and federal security regulations.

How do we know that you do what you say?

Jopari’s applications are certified for SOC 2 Type II, by the American Institute of Certified Public Accountants (AICPA). This means that an independent auditor has examined the controls protecting the data in our systems (including logical security, privacy, and data center security) and assured that these controls are in place and operating effectively. For inquiries relating to Jopari’s SOC 2 Type II certification, please contact info@jopari.com for more information.

How does Jopari protect against hackers, hacktivists, governments and other intruders?

Our data center is built with custom-designed servers, running our own operating system for security and performance. Jopari’s data center uses custom hardware running a custom hardened operating system and file system. Each of these systems has been optimized for security and performance. Jopari has 24/7 security monitoring controls in place that allow us to quickly respond to any threats or weaknesses that may emerge. All data is encrypted in transit and at rest per the National Institute of Standards and Technology (NIST) guidelines that comply with state and federal security mandates. To protect against intrusion our Jopari PGP Key is RSA 2048, SHA-2-256 and AES 256. The keys are changed periodically as another security compliance control.

Does Jopari encrypt my data?

Yes, your data is encrypted at three different levels. In transit the data is encrypted using 256-bit Transport Layer Security (TLS) and at rest in a flat file PGP3. Your data is also encrypted in the database using AES 256-bit Transport Layer Security (TLS).

How do I know that other customers sharing the same servers can’t access my data?

Your data is logically protected as if it were on its own server. Unauthorized parties cannot access your data. In fact, all user accounts are protected by this secure architecture that ensures that one user cannot see another user’s data. This is similar to how customer data is segmented in other shared infrastructures, such as online banking applications.

We do everything in our power to protect you and your businesses from attempts to compromise your data. We vigorously resist any unlawful attempt to access our customers’ data. Jopari used an independent auditor that has verified that our privacy practices and contractual commitments comply with state and federal Privacy regulations.

Does giving Jopari access to my data create a security risk? How does Jopari ensure that its employees do not pose a threat?

Jopari’s security practices are verified and certified by third-party auditors. An independent auditor has certified and examined the controls present in our data centers, infrastructure, and operations. Jopari employment practices require employees to be subject to background investigations based on their level of access. Any employee access is governed by a policy of “least privilege access,” which means that access is only granted to the information and resources that are necessary for the execution of the assigned task.

When can Jopari employees access my account?

Jopari may only access data in your account in strict compliance with our Privacy Policy and your Customer Agreement. We also further describe in your Business Associate Agreement and Service Level Agreement our commitment to protecting your data. For purposes of providing technical support, an administrator from your domain may choose to grant the Jopari Support team permission to access accounts to resolve a specified issue, if applicable.

Do we maintain ownership of the information we send to Jopari?

The data you have sent for business processing belongs to you. We do not use your information for anything but the purposes specified in your agreement. You have control over your data. We comply with the HIPAA Media Destruction and Disposal Regulations.

Jopari has built a proven infrastructure that provides ourcustomers with reliable secure technology solutions for the healthcare andpayment industry.

What does Jopari do to plan for disasters or the departure of key staff?

Jopari has a business continuity plan for its data centers and production operations. This plan accounts for major disasters such as earthquakes and public health crises, and it assumes people and services may be unavailable. This plan is designed to enable continued delivery of our services to our customers.

How can Jopari be so reliable?

Jopari’s application and network architecture is designed for maximum reliability and uptime. Jopari’s computing platform assumes ongoing hardware failure and uses robust software failover to withstand disruption. All Jopari systems are inherently redundant by design, and each subsystem is not dependent on any particular physical or logical server for ongoing operation to ensure you always have access to your data.

Will my data always be available? What happens in case of downtime?

Jopari’s application and network architecture is designed for maximum reliability, redundancy, and uptime. If a machine—or even an entire data center—fails, your data will still be accessible.

How reliable are Jopari’s applications?

Jopari offers a 99.9% Service Level Agreement (SLA) for covered services. Jopari does have scheduled downtime or maintenance; however, this is not done during business processing hours. To minimize service interruption due to hardware failures, natural disasters, or other incidents, Jopari has built a highly redundant infrastructure of data center sites. Jopari has a Recovery Point Objective (RPO) target of zero, and our Recovery Time Objective (RTO) target is instant failover (or zero).

Jopari is committed to providing you a secure infrastructurethat is compliant with state and federal security regulations to protect yourinformation. Jopari used an independent auditor that has verified that oursecurity practices and contractual commitments comply with state and federalsecurity regulations.

Where is my data stored?

Your data is stored at Rackspace, our hosted site, with backup redundant sites. Jopari’s computing clusters are designed with resiliency and redundancy in mind, eliminating any single point of failure and minimizing the impact of common equipment failures and environmental risks. The data center is monitored 24/7 with security and privacy controls that meet state and federal security regulatory requirements to ensure your data is secured.

Who at Jopari can look at my data?

Access rights are based on a Jopari employee’s job function and role. The access rights use the concepts of least privilege and need-to-know—commensurate with the employee’s defined responsibilities. Access rights are based on the National Institute of Standards and Technology (NIST) control requirements as specified by state and federal regulatory requirements. Jopari employees are only granted a limited set of default permissions to access company resources. Jopari requires the use of a unique user ID for each employee. This account is used to identify each person’s activity on Jopari’s network, including any access to employee or customer data.

How do I know if there is an issue with my data?

For security events that may affect confidentiality, integrity, or availability of systems or data, Jopari has an incident management process in place. This process specifies courses of action and procedures for notification, escalation, mitigation, and documentation. To help ensure the swift resolution of security incidents, the Jopari Incident Response Team is available 24/7. In the case of a security event, a member of our Incident Response Team will notify the affected customers of the incident that affects the confidentiality, integrity, or availability of their data. Once an initial notification is made, we follow state and federal breach incident procedures for investigation, risk assessment, and follow-up notifications and calls as needed for the affected parties to understand the incident and take remediation action as appropriate and required by state and federal law.

What do you use my data for?

Jopari processes your data to fulfill our contractual obligation to deliver our services. Our clients own their data, not Jopari. We do not sell your data to third parties.

Does Jopari encrypt my data?

Yes, your data is encrypted at three different levels. In transit the data is encrypted using 256-bit Transport Layer Security (TLS) and at rest in a flat file PGP3. Your data is also encrypted in the database using AES 256-bit Transport Layer Security (TLS).

How does Jopari protect against hackers, hacktivists, governments and other intruders?

Our data center is built with custom-designed servers, running our own operating system for security and performance. Jopari’s data center uses custom hardware running a custom hardened operating system and file system. Each of these systems has been optimized for security and performance. Jopari has 24/7 security monitoring controls in place that allow us to quickly respond to any threats or weaknesses that may emerge. All data is encrypted in transit and at rest per the National Institute of Standards and Technology (NIST) guidelines that comply with state and federal security mandates. To protect against intrusion our Jopari PGP Key is RSA 2048, SHA-2-256 and AES 256. The keys are changed periodically as another security compliance control.

How do I know that other customers sharing the same servers can’t access my data?

Your data is logically protected as if it were on its own server. Unauthorized parties cannot access your data. In fact, all user accounts are protected by this secure architecture that ensures that one user cannot see another user’s data. This is similar to how customer data is segmented in other shared infrastructures, such as online banking applications.