Haekka Security

What is Haekka

Haekka is a unique training platform that seamlessly integrates with user apps and workflows. Our intelligent platform provides personalized knowledge and learning opportunities to users exactly when they need it most. By embedding training into work processes, we address a critical gap in SaaS apps where modern work takes place. Our approach leads to better engagement from users, increased effectiveness of training, and empowers managers with valuable data to drive continuous learning, improvement, and desired outcomes.

Haekka Runs on Trust

At Haekka, we prioritize security in everything we do. We have implemented rigorous security and privacy policies and procedures to safeguard the confidentiality, integrity, and availability of our services, systems, and data. All employees and contractors are required to comply with these policies and procedures, which are easily accessible and regularly reviewed to ensure compliance. Furthermore, we conduct thorough background checks on all employees before granting them access to any Haekka systems, networks, apps, or data, providing an extra layer of protection.

Human-factor Security

At Haekka, we believe that security awareness is essential for all employees. That's why we require all new hires to complete security awareness training within 14 days of their start date, and we provide annual training updates to ensure that everyone is up to date on the latest best practices. Additionally, we send out weekly security and privacy focused training to all employees through Slack, keeping security at the forefront of everyone's minds.

Data Processed

At Haekka, we are committed to protecting our customers' privacy and follow a philosophy of only processing the minimum amount of personally identifiable information (PII) necessary to deliver our unique value. As part of this commitment, we limit the data we collect to only what is required to provide our services. The following information represents the types of data we process:

  1. User's full name as provided by Slack
  2. User's work email as provided by Slack

Slack Permissions

Haekka is a security headquarters that seamlessly integrates with Slack. Our platform helps companies engage with their employees on security and privacy topics through personalized messaging and training. For a complete and up-to-date list of the permissions required by Haekka in Slack, please visit https://slack.com/apps/A01A35CS7TR-haekka-security-awareness-training?tab=settings&next_id=0. To ensure privacy and security, all messages sent from Haekka to users are exclusively delivered through the Haekka Slack app and not in public channels, private channels, or direct messages.

Encryption

Haekka encrypts all data at rest and in transit using:

  • AES-256 encryption on all stored data
  • TLS 1.2 or higher for all connections

Audit Logging

Haekka logs all access requests, database changes, and retains logs for 90 days.

Access Controls

Strict access controls are enforced on all production systems:

  • Default accounts are deactivated
  • All accounts are unique
  • Login is required to all systems
  • MFA is enforced on all cloud environments

Single Sign-On (SSO)

Haekka currently supports sign-on with Slack.

  • With "Sign in with Slack", Haekka supports the various OAuth and 2fa methods as provided by Slack.

Team Management

Haekka supports roles for admins and users.

  • Admins can create, edit, and assign content
  • Admins can view results and download audit evidence
  • Users can take training and request certificates

Physical Security

Haekka operates as a distributed workforce without any offices or data centers. Our platform and data is securely managed with cloud services from Heroku and Amazon Web Services. Furthermore, all of our employee applications are delivered via Software-as-a-Service (SaaS) directly to employees' devices.

Cloud Services

At Haekka, we take the security and privacy of our customers' data very seriously. To ensure the highest level of protection, we use data centers managed by Amazon and Heroku that are certified by ISO 27001 and FISMA. Amazon and Heroku are renowned for their extensive experience in constructing and operating large-scale data centers, which is reflected in the robust infrastructure of the AWS platform.

All AWS and Heroku data centers are located in nondescript facilities, and feature military-grade perimeter controls, setback protection, and other natural boundary protections. Physical access is strictly regulated by professional security personnel who use state-of-the-art intrusion detection systems, video surveillance, and other electronic means at both the perimeter and building ingress points. Authorized staff must complete two-factor authentication at least three times to access the data center floors. All visitors and contractors must provide identification and be accompanied by authorized personnel at all times. Access to data center facilities and information is only granted to employees who have a legitimate business need. If an employee no longer requires such access, their privileges are immediately revoked, even if they remain an employee of Amazon, Amazon Web Services, or Heroku.

To ensure the security and confidentiality of our customers' data, all access by Amazon employees is logged and routinely audited. For more information on AWS security, please visit https://aws.amazon.com/security.

Environmental Safeguards

Haekka's cloud providers take extensive measures to ensure the safety and reliability of their data centers. Facilities are equipped with automatic fire detection and suppression equipment, utilizing smoke detection sensors and wet-pipe, double-interlocked pre-action, or gaseous sprinkler systems. Data center electrical power systems are fully redundant and maintainable 24/7, with Uninterruptible Power Supply (UPS) units providing backup power for critical and essential loads. In the event of an electrical failure, generators provide backup power for the entire facility.

To prevent overheating and reduce the possibility of service outages, cloud providers maintain a constant operating temperature for servers and other hardware with climate control systems. These systems are monitored by data center personnel to ensure temperature and humidity are at optimal levels. Additionally, staff regularly perform preventative maintenance to ensure equipment remains operable. Data centers are located in nondescript facilities with military-grade perimeter control, setback protection, and other natural boundary protections. Physical access is strictly regulated by professional security personnel, and authorized staff must complete two-factor authentication to access the data center floors. All access, whether physical or electronic, is logged and routinely audited.

For additional information on AWS, see: https://aws.amazon.com/security

Security Reporting

If you want to report a security finding — vulnerability, threat, etc. — please email us at hello@haekka.com.

Security Assessments and Compliance

Data Centers

Haekka's physical infrastructure is hosted and managed within Amazon's and Heroku's secure data centers and utilizes Amazon Web Services (AWS) and Heroku technology. Amazon and Heroku conduct regular risk management and compliance assessments to meet industry standards. Their data center operations have received accreditation under:

  • ISO 27001
  • SOC 1 and SOC 2/SSAE 16/ISAE 3402 (Previously SAS 70 Type II)
  • PCI Level 1
  • FISMA Moderate
  • Sarbanes-Oxley (SOX)

PCI

Haekka does not process or store any financial information. All PCI-covered data and transactions are managed by our payment provider, Stripe.

Penetration Testing and Vulnerability Assessments

Haekka conducts internal penetration testing using best practice workflows and playbooks. Additionally, Haekka security team members subscribe to vulnerability mailing lists and boards, reviewing all relevant vulnerabilities.

Network Security

Firewalls are implemented to restrict access to systems from external networks and within systems internally. The default setting is to deny all access, and only authorized ports and protocols are allowed based on the requirements of the business. Each system is assigned to a firewall security group that is based on function. The security groups restrict access to only the necessary ports and protocols for a system's particular function to reduce risk.

To further isolate customer applications, host-based firewalls restrict them from establishing localhost connections over the loopback network interface. Host-based firewalls also allow further limiting of inbound and outbound connections as needed. Our infrastructure uses TCP Syn cookies and connection rate limiting to mitigate DDoS attacks, in addition to maintaining multiple backbone connections and internal bandwidth capacity that exceeds the bandwidth supplied by the Internet carrier. We work closely with our providers to respond quickly to events and enable advanced DDoS mitigation controls when required.

Managed firewalls prevent IP, MAC, and ARP spoofing between virtual hosts and on the network to ensure that spoofing is not possible. Packet sniffing is prevented by the infrastructure, including the hypervisor, which does not deliver traffic to an interface that is not addressed. Haekka employs application isolation, operating system restrictions, and encrypted connections to further mitigate risk at all levels.

Port scanning is not allowed and any events are investigated by AWS or Heroku. Port scans are stopped as soon as detected.

Backups

Haekka leverages managed storage and database services from AWS and Heroku. Backups are performed on all of these storage and database instances.

Disaster Recovery

Haekka has an established and tested disaster recovery plan.

Customer Data Retention and Destruction

Haekka does not retain data after customers terminate contracts. AWS and Heroku decommission hardware in compliance with DoD 5220.22-M (“National Industrial Security Program Operating Manual “) or NIST 800-88 (“Guidelines for Media Sanitization”) to destroy data.

Privacy

Haekka takes privacy seriously. Our published privacy policy can be found here → https://www.haekka.com/privacy-policy

Access to Customer Data

Haekka's employees do not typically access or engage with client data or applications as part of their regular duties. However, in certain circumstances, Haekka may be asked to interact with customer data or applications for support reasons or in compliance with legal requirements. Access to customer data is controlled, and all access by Haekka personnel is subject to customer authorization or government mandates. The reason for access, staff actions, and support start and end times are all documented.

Top