Security

At Fishbowl, protecting your data is a top priority. We continuously improve our security measures and maintain dedicated expertise across engineering, operations, incident response, compliance, and application security.

Data Encryption

All external and database connections use TLS 1.2+ encryption. Data at rest in AWS services and Fishbowl MySQL is encrypted with AES-256.

Penetration Testing

Fishbowl contracts twice-per-year security audits in the form of white-hat penetration tests, with regular SAST and DAST scanning.

Vulnerability Assessments

Regular automated vulnerability scanning and code analysis with SAST integration and OWASP-aligned review processes.

Security Training

Developer training focused on OWASP Top 10, secure coding practices, input validation, parameterized queries, and output encoding.

Incident Response

Documented incident response plan to handle security breaches promptly with clear stakeholder communication protocols.

Multi-factor Authentication

MFA codes via email with 6-digit codes that expire after 10 minutes. Configurable token frequency and required for API integrations.

Business Continuity

Customer data housed in U.S. data centers with live replication. Automatic rolling seven-day backups for point-in-time recovery.

Disaster Recovery

Live replication of all customer data between primary U.S. data centers with tested DR failover procedures.

SOC 2 Compliance

Fishbowl Hosted Services is SOC 1 Type II and SOC 2 Type II certified, with ISO and PCI compliance.

Privacy

Adherence to GDPR and CCPA practices. Data Privacy Agreements (DPAs) maintained with integration partners. PII secured based on CCPA standards.

Physical Infrastructure

Customer data housed in primary U.S. data centers with live replication between geographically distributed sites.

Vendor Risk Management

Key compliance frameworks applied for vendor evaluation with regular third-party security audits and penetration tests.

High Availability

24/7 oversight by a Security Operations Center with regular backups, managed updates, and defined maintenance windows.