Acquia's platform was built from the ground up with security in mind. Customers get a secure environment with an array of strong access and authentication controls, as well as different firewall controls for best-in-class defensive security capabilities. Each of the following features ensure your site is protected from day one.
Multiple layers of firewalls ensure that only trusted network traffic is permitted to and from your Acquia environment.
Strong authentication methods are critical to a secure cloud. Acquia provides multifactor authentication support to prevent unauthorized access to your Acquia Cloud environment.
A fundamental value proposition of the Acquia Cloud Platform is the timely identification, triage, and resolution of security vulnerabilities.
Security Event Monitoring
Acquia uses a security event log storage and monitoring platform. Security alerts are constantly monitored and tuned by skilled analysts to ensure the integrity of the systems your site is running on.
Secure File Permissions
The majority of attacks against sites attempt to take control of the web service. The Acquia Platform has restricted file permissions by default. This prevents any unauthorised changes to your site code and any malicious file uploads from executing.
Disaster Recovery and Site Backups
Acquia maintains a comprehensive backup solution for disaster recovery. The Acquia Cloud provides customers with easy to access code, file, and database backups of their site.
Acquia has a comprehensive compliance portfolio that validates the security of our platform. This compliance portfolio includes a variety of industry specific audits and certifications performed by independent third parties. These independent evaluations rate the design and operational effectiveness of Acquia’s security controls.
SSAE16/ISAE 3402: Service Organization Control (SOC 1) Type II
Statement on Standards for Attestation Engagement (SSAE) No. 16 is an attestation standard used to evaluate the design and operating effectiveness of Acquia’s information technology controls that impact our customers’ own internal controls over financial reporting.
SSAE 16 is an American auditing standard issued by the American Institute of Certified Public Accountants (AIPCA). In order to meet the requirements of international accounting standards, Acquia receives a “SSAE 16/ISAE 3402 Combo Report.” The ISAE 3402 report provides coverage to support the financial reporting requirements of International organizations.
Service Organization Control (SOC 2) Type II
Acquia’s SOC 2 Report includes an assessment against the Common Criteria principles of Security, Availability, and Confidentiality.
Payment Card Industry - Data Security Standard (PCI-DSS)
For customers that process, store, or transmit cardholder data Acquia provides a PCI-DSS compliant hosting platform to ensure the protection of your customer's cardholder data in accordance with PCI-DSS version 3.2.
Health Insurance Portability and Accountability Act (HIPAA)
The Acquia Cloud Platform meets the requirements of the HIPAA Security Rule and HITECH for electronic Protected Health Information (ePHI).
Federal Education Records Privacy Act (FERPA)
The Federal Education Records Privacy Act (FERPA) mandates that institutions protect their students’ educational records and personal data. For Acquia’s higher education customers, they rest easy knowing that Acquia Cloud’s security and compliance controls provide FERPA-compliant digital experiences. Multi-layered cloud security controls, configurable user permissions, and built-in backups and disaster recovery make it easy to achieve FERPA compliance requirements and additionally, all Acquia Cloud services are monitored by a dedicated incident response team. FERPA. Check!
Acquia is ISO 27001 certified. You can see our certification mark here. ISO/IEC 27001:2013 (ISO 27001) is a globally recognized security standard driven by the implementation of an information security management system (ISMS).
The Acquia Cloud Platform is FedRAMP compliant, and detail on authorizing agencies can be viewed in the FedRAMP Marketplace.
For customers on the Acquia Platform, we offer additional layers of security on top of our built-in protection. The Acquia Cloud Edge family of products includes Acquia Cloud Edge Protect and Acquia Cloud Edge CDN. We also offer Acquia Cloud Shield, an isolated section of Acquia Cloud.
Acquia Cloud Edge Protect
Acquia Cloud Edge Protect mitigates the effects of DDoS and application level attacks for our Acquia Cloud Enterprise (ACE) and Acquia Cloud Site Factory (ACSF) customers.
Acquia Cloud Edge CDN
Acquia Cloud Edge CDN provides a global content delivery network (CDN) that accelerates the delivery of your site to visitors, wherever they may be.
Acquia Cloud Shield
Acquia Cloud Shield is a dedicated, logically isolated environment within Acquia Cloud that has a customizable network configuration.
Acquia Cloud VPC Family
Data is the lifeblood of your organization, and at Acquia, we recognize the importance of the proper classification of information and handling of data. Our ‘Acquia Cloud VPC Family’ is a suite of virtual private cloud (VPC) products designed to provide elevated and compliant protection for sensitive data.