Trust Center

Security & privacy at PeriNimble Our security posture, in the open.

PeriNimble recognizes that the confidentiality, integrity and availability of information and data created, maintained and hosted by us are vital to the success of the business and privacy of our partners.

3

compliance frameworks

31

security controls

41

policies & documents

5

subprocessors

Our commitment

Clear information about how we protect your data

As a service provider/product, we understand the importance in providing clear information about our security practices, tools, resources and responsibilities within PeriNimble so that our customers can feel confident in choosing us as a trusted provider.

This Security Posture highlights high-level details about our steps to identify and mitigate risks, implement best practices, and continuously develop ways to improve.

Founded in 2022.

Compliance frameworks

Here are the compliance frameworks that PeriNimble follows which showcases our adherence to industry-standard security guidelines and practices.

ISO 27001 badge

Compliant

ISO 27001 v2022

The updated version of the ISO 27001 standard, reflecting the latest best practices and improvements in information security management.

SOC 2 badge

Compliant

SOC 2

SOC 2 is a voluntary compliance standard for service organizations, developed by the American Institute of CPAs (AICPA), which specifies how organizations should manage customer data. The standard is based on the following Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

ISO 27001 badge

Compliant

ISO 27001

A globally recognized standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

Security controls

Here are the controls implemented at PeriNimble to ensure compliance, as a part of our security program.

Product security (1)

Situational Awareness For Incidents — Entity maintains a record of information security incidents, its investigation, and the response plan that was executed in accordance with the policy and procedure defined to report and manage incidents.

Data security (1)

Termination of Employment — Entity ensures logical access that is no longer required in the event of termination is made inaccessible in a timely manner.

App security (1)

Approval of Changes — Entity has established procedures for approval when implementing changes to the operating environment.

Endpoint security (4)

Malicious Code Protection (Anti-Malware) — Where applicable, Entity ensures that endpoints with access to critical servers or data must be protected by malware-protection software.

Full Device or Container-based Encryption — Where applicable, Entity ensures that endpoints with access to critical servers or data must be encrypted to protect from unauthorized access.

Endpoint Security Validation — Entity has set up measures to perform security and privacy compliance checks on the software versions and patches of remote devices prior to the establishment of the internal connection.

Endpoints Encryption — Entity requires that all critical endpoints are encrypted to protect them from unauthorized access.

Corporate security (24)

Code of Business Conduct — Entity has a documented policy to define behavioral standards and acceptable business conduct.

Organizational Structure — Entity maintains an organizational structure to define authorities, facilitate information flow and establish responsibilities.

Roles & Responsibilities — Entity has established procedures to communicate with staff about their roles and responsibilities.

New Hire Policy Acknowledgement — Entity has established procedures for new staff to acknowledge applicable company policies as a part of their onboarding.

Security & Privacy Awareness — Entity provides information security and privacy training to staff that is relevant to their job function.

Periodic Policy Acknowledgement — Entity has established procedures for staff to acknowledge applicable company policies periodically.

Automated Reporting — Entity has provided information to employees, via various Information Security Policies/procedures, on how to report failures, incidents, concerns, or other complaints related to the services or systems provided by the entity in the event there are problems.

Risk Framing — Entity performs a formal risk assessment exercise annually, as per documented guidelines and procedures, to identify threats that could impair systems' security commitments and requirements.

Risk Assessment — Each risk is assessed and given a risk score in relation to the likelihood of it occurring and the potential impact on the security, availability, and confidentiality of the Company platform. Risks are mapped to mitigating factors that address some or all of the risk.

Fraud — Entity considers the potential for fraud when assessing risks. This is an entry in the risk matrix.

Third-Party Criticality Assessments — Entity performs a formal vendor risk assessment exercise annually to identify vendors that are critical to the systems' security commitments and requirements.

Assigned Cybersecurity & Privacy Responsibilities — Entity's Senior Management assigns the role of Information Security Officer who is delegated to centrally manage, coordinate, develop, implement, and maintain an enterprise-wide cybersecurity and privacy program.

Internal Audit using Sprinto — Entity uses Sprinto, a continuous monitoring system, to track and report the health of the information security program to the Information Security Officer and other stakeholders.

Periodic Review & Update of Cybersecurity & Privacy Program — Entity's Senior Management reviews and approves the state of the Information Security program including policies, standards, and procedures, at planned intervals or if significant changes occur to ensure their continuing suitability, adequacy, and effectiveness.

Management Review of Org Chart — Entity's Senior Management reviews and approves the Organizational Chart for all employees annually.

Management Review of Risks — Entity's Senior Management reviews and approves the "Risk Assessment Report" annually.

Management Review of Third-Party Risks — Entity's Senior Management reviews and approves the "Vendor Risk Assessment Report" annually.

Subservice organization evaluation — Entity reviews and evaluates all subservice organizations periodically, to ensure commitments to Entity's customers can be met.

Segregates Roles and Responsibilities — Entity's Senior Management segregates responsibilities and duties across the organization to mitigate risks to the services provided to its customers.

Asset Ownership Assignment — Entity has set up mechanisms to assign and manage asset ownership responsibilities and establish a common understanding of asset protection requirements.

Data Governance — Entity maintains a list of legal, statutory, and regulatory requirements relevant to information security.

New Hire Security & Privacy Training Records — Entity has established procedures for new staff to complete security and privacy literacy training as a part of their onboarding.

Periodic Security & Privacy Training Records — Entity documents, monitors, and retains individual training activities and records.

Inventory of Endpoint Assets — Entity develops, documents, and maintains an inventory of organizational endpoint systems, including all necessary information to achieve accountability.

Policies & documents

Here are the important security policies and documents which are a part of PeriNimble's compliance program.

Policies are shared on request through the Trust Center portal.

Policies (37)

Code of Business Conduct Policy

Acceptable Usage Policy

Asset Management Procedure

Vendor Management Policy

SDLC Procedure

Encryption Policy

Business Continuity & Disaster Recovery Policy

HR Security Procedure

Physical & Environmental Security Policy

Endpoint Security Policy

Business Continuity Plan

Data Breach Notification Policy

Physical and Environmental Security Procedure

Compliance Policy

Personal Data Breach Notification Procedure

Incident Management Procedure

Media Disposal Policy

HR Security Policy

Asset Management Policy

Operations Security Procedure

PHI Data breach Notification Procedure

Data Protection Policy

Privacy By Design Policy

Operation Security Policy

System Acquisition and Development Lifecycle Policy

Data Classification Policy

Risk Assessment & Management Policy

Organization of Information Security Policy

Network Security Procedure

Communications & Network Security Policy

Access Control Procedure

Incident Management Policy

Data Retention Policy

Information Security Policy

Compliance Procedure

Access Control Policy

Vendor Management Procedure

Documents (4)

Subprocessors

Here are the subprocessors that PeriNimble uses to process data in its infrastructure and business operations.

Github App

Development software

Atlassian (Jira)

Development Documentation

Gusto

HRMS

Confluence

Collaboration & Productivity

Microsoft Teams

Collaboration & Productivity

Trusted by

Check out PeriNimble's customer that trust us for our robust security program.

Util Assist

TRC

Landis+Gyr

CrescoNet

Meridian Integration

Need our security documentation?

Request policies, reports and questionnaires through our Trust Center — or talk to our team.

Open the Trust Center