At Fishbowl, protecting your data is a top priority. We continuously improve our security measures and maintain dedicated expertise across engineering, operations, incident response, compliance, and application security.
All external and database connections use TLS 1.2+ encryption. Data at rest in AWS services and Fishbowl MySQL is encrypted with AES-256.
Fishbowl contracts twice-per-year security audits in the form of white-hat penetration tests, with regular SAST and DAST scanning.
Regular automated vulnerability scanning and code analysis with SAST integration and OWASP-aligned review processes.
Developer training focused on OWASP Top 10, secure coding practices, input validation, parameterized queries, and output encoding.
Documented incident response plan to handle security breaches promptly with clear stakeholder communication protocols.
MFA codes via email with 6-digit codes that expire after 10 minutes. Configurable token frequency and required for API integrations.
Customer data housed in U.S. data centers with live replication. Automatic rolling seven-day backups for point-in-time recovery.
Live replication of all customer data between primary U.S. data centers with tested DR failover procedures.
Fishbowl Hosted Services is SOC 1 Type II and SOC 2 Type II certified, with ISO and PCI compliance.
Adherence to GDPR and CCPA practices. Data Privacy Agreements (DPAs) maintained with integration partners. PII secured based on CCPA standards.
Customer data housed in primary U.S. data centers with live replication between geographically distributed sites.
Key compliance frameworks applied for vendor evaluation with regular third-party security audits and penetration tests.
24/7 oversight by a Security Operations Center with regular backups, managed updates, and defined maintenance windows.