Data and Cyber Security FAQs
At Diligentsia, we keeping your data secure is very important. Whether you're storing sensitive client information or running your company's operations, we want you to know that your data is protected. This article answers some of the most common questions about data security and privacy, helping you understand how we keep your information safe. From encryption methods and compliance with laws like GDPR to how your data is backed up and who has access to it, we’ll walk you through the key measures in place to give you peace of mind when using our platform. These FAQs should answer most of your questions and show that your data and info is secured tightly.
Q: How do you ensure the security of our data on your platform?
We implement robust security measures, including encryption, regular security audits, and strict access controls, to ensure your data is protected at all times.
Q: What encryption methods do you use to protect our data?
All data is encrypted both at rest and in transit using industry-standard protocols like AES-256.
Q: Do you comply with data protection regulations like GDPR?
Yes, we are fully compliant with relevant data protection regulations such as GDPR, ensuring your data is handled according to legal requirements.
Q: Where is our data stored?
Your data is securely stored on AWS servers located in regions that comply with international security standards. Your data is NOT sent to, or held on servers in the USA.
Q: Who has access to our data?
Access to your data is strictly controlled and limited to authorized personnel who require it for support purposes; all access is logged and monitored. In addition to our own staff and contractors, you yourself can monitor access to your companies’ data on our platform through a team permissions structure. You control access of your company’s data to advisors and investors.
Q: How do you handle data backups and disaster recovery?
We perform regular cloud data backups performed and have a comprehensive disaster recovery plan to ensure data integrity and availability.
Q: What measures are in place to prevent unauthorized access?
We employ multi-factor authentication, role-based access controls, and monitoring to prevent unauthorized access.
Q: Do you have any third-party security certifications?
Yes, we are in compliance with Crest, demonstrating our commitment to security best practices. This has been provided subsequent to audits undertaken by an independent third party specialist cybersecurity organization that is frequently used by large UK private equity firms to undertake cybersecurity audits on their portfolio companies and potential investments. They are Crest accredited and have performed their audit in accordance with those standards.
Q: How do you handle data breaches?
In the unlikely event of a data breach, we have a predefined incident response
plan to quickly address the issue and notify affected parties as required by law.
Q: Can we audit your security practices?
We welcome audits and can provide detailed documentation of our security practices upon request.
Q: How do you ensure compliance with industry-specific regulations?
We stay up-to-date with industry regulations and adjust our practices to ensure
compliance where required.
Q: What is your policy on data ownership?
You retain full ownership of your data at all times; we only process it as per our
agreement.
Q: How is client data segregated?
Client data is logically segregated to prevent any cross-access between different
clients' data. We hold your data in the cloud on separate servers from those used
for development, in industry-standard databases.
Q: Do you use any subcontractors or third-party services that have access to our data?
We use trusted third-party services like AWS for infrastructure. Any subcontractors
with access to data are thoroughly vetted and bound by strict confidentiality
agreements.
Many of our services add value through the use of AI. Where we use third party
AI-platforms we make this clear in our reporting. However, we DO NOT access
the contents of data files you provide us nor send these to AI platforms, but may
send the text of filenames out in applications such as our Digital Assistant to
assist in the filing of the files within the Data Repository.
Q: What is your data retention policy?
We retain data as long as necessary to provide our services, after which it is securely deleted in accordance with our data retention policy.
Q: How do you handle data deletion requests?
Upon request, we will securely delete your data from our systems and confirm the
deletion.
Q: Do you support data portability?
Not as such, although you can:
a) Download .pdf files of each of your module reports.
b) Sync our Data Repository with your chosen cloud provider – Drive, Sharepoint or
Dropbox. Please note that if you want to backup your files added as part of our
AppStore modules or AnyList Checklist Builder modules, you will need to create
additional user-defined sections within your Data repository to ensure that they
are backed up to your chosen Data Room.
Q: What kind of support do you offer in case of issues?
We offer 24/7 bot-based customer support to assist you with any issues or
concerns you may have, and human customer support through our book a call
feature through our web site.
Q: How do you keep your software updated against new security threats?
We regularly update our software and infrastructure to protect against emerging
security threats, following best practices and threat intelligence.
Q: Can you provide references or case studies from other clients?
Yes, we can provide references demonstrating how we've successfully secured
data.
Q: What happens if you go out of business?
Within our Data Repository you can sync any files you upload with your chosen
Data Room (Drive, Dropbox, Sharepoint) and therefore treat your Data Room as a
backup, and all reports can be downloaded in .pdf form.
Q: Who owns Diligentsia? Who is Mark Bernstein?
Diligentsia Limited is majority-owned by Mark Bernstein ACA, the founder and a
UK resident. He qualified as an accountant with EY and has sat on VC-backed
and listed company boards for thirty years. He has taken a number of early-stage
businesses through investment, growth to IPO.
Q: Who are Diligentsia’s shareholders?
Diligentsia Limited is majority-owned by Mark Bernstein ACA, the founder and a
UK resident. The remainder is owned by the management team.
Q: Is my data safe with you?
No one can guarantee 100% security. However, we have taken what we believe
to be reasonable steps to protect your and your clients’ data – this is the bedrock
of our business. Our platform and your data is hosted on AWS in the cloud, we
take robust measures, involving a third party cybersecurity expert organisation
and have detailed internal policies. If you have concerns and want further
information, we are delighted to share this with you (once we have validated you!).
Q: Do you store my credit card information?
No – our payments services are provided by Stripe (www.stripe.com). We do not
store your credit card information on our platform.
Q: Is Diligentsia Limited FCA regulated?
No, we are advised that we are not required to be at this stage.
Q: Do you sell our client data to third parties?
No, we do not sell your data to third parties! Please see our Data Privacy Policy
(available on our website – www.diligentsia.co.uk) for further information.
Q: Can we limit access of our advisors and investors to our company data on your platform?
Yes. The permissions features on our platform allow you to determine who gets to
see what.
Troubleshooting FAQs: Data and Cyber Security
Q: Why can’t I access my company data?
A: Ensure you have the correct permissions and are logged in with the appropriate account. Contact your admin or support if the issue persists.
Q: How do I verify my data is encrypted?
A: All data is encrypted automatically during storage and transit. You can check encryption settings in your user agreements or contact support for more information.
Q: Why is my data sync not working with the Data Room?
A: Check your internet connection and verify that your chosen cloud provider (Drive, Dropbox, or SharePoint) is connected. Reauthorize the connection if necessary.
Q: What should I do if I suspect unauthorized access?
A: Immediately change your password, enable two-factor authentication, and review the audit logs to identify any suspicious activity. Contact support for further assistance.
Q: Why can’t I see my data after uploading it?
A: Refresh your dashboard and check the upload logs. If the issue persists, confirm that the data was uploaded to the correct folder in the Data Repository.
Q: How do I confirm my data backup is complete?
A: Check the backup logs in the Data Repository or sync reports for confirmation. You can also verify files in your connected Data Room.
Q: What should I do if I forget to download my certification reports?
A: Certifications are saved in your account. Navigate to the Certification Module in your dashboard to re-download them.
Q: Why was my data deletion request not processed?
A: Ensure the request was submitted correctly. If it’s been delayed, contact support to confirm the status of your request.
Q: Why can’t I delete certain data files?
A: Files tied to active processes or modules may require additional permissions or manual intervention. Review your access permissions or contact support.
Q: What do I do if my permissions are incorrect?
A: Contact your admin or review your user permissions in the settings. Only account owners or designated admins can modify permissions.
Q: Why can’t I audit my team’s access?
A: Ensure you have the appropriate permissions to view audit logs. Navigate to the “Logs” section of your dashboard to review changes.
Q: How do I report a potential security vulnerability?
A: Contact support immediately and provide details about the suspected vulnerability. Our team will investigate and take action as necessary.
Q: Why is multi-factor authentication (MFA) not working?
A: Ensure your authenticator app, SMS, or email is set up correctly. Check for time synchronization issues on your devices.
Q: How do I confirm my data is GDPR-compliant?
A: All data stored on our platform complies with GDPR. Review your Data Privacy Policy or contact support for additional documentation.
Q: Why am I unable to sync with my chosen cloud provider?
A: Ensure you’ve authorized Diligentsia to access your cloud account. Check for API issues with your provider and retry the connection.
Q: Why can’t I access the audit log?
A: Only users with admin or specific permissions can access the audit log. Contact your account owner to grant you the necessary access.
Q: How do I verify the security of my payment information?
A: Payments are processed securely through Stripe, and no credit card information is stored on the platform. Contact Stripe for transaction details if needed.
Q: Why isn’t my third-party integration working?
A: Confirm that the third-party service (e.g., Drive, Dropbox) is supported and properly authorized. Reconnect the integration and try again.
Q: What should I do if my platform access is revoked?
A: Contact your admin to verify if access was intentionally removed. If it was unintentional, they can reinstate your permissions.
Q: How do I verify compliance with industry-specific regulations?
A: Review the documentation provided in your dashboard or contact support for detailed compliance reports tailored to your industry.