Vendor Cloud Questionnaire
Data ownership – Does the contract clearly document City is sole owner of the Data & meta Data used for the Cloud service offered?
Yes – all data belongs to the City.
Where is the data hosted? Are backups of the customer data performed? Please provide frequency of backups, location of backups and any other relevant details.
All data is hosted and processed on Google Cloud Platform (GCP). Our data is backed by PostgreSQL, an open source object-relational database with more than 30 years in the market. Database is backed up daily and our current retention policy is to keep back-ups for a week. All backup files are again managed by GCP.
All uploaded files are versioned by GCP.
Confirm Data will not be used for Data mining etc.
Confirmed.
Will the vendor guarantee they will not move City data to another hosting jurisdiction without prior notification?
Confirmed – will need to be added to contract
All uploaded files are versioned by GCP.
Does the vendor use a 3rd party to host data? Who?
All data is hosted by GCP.
Will you delete customer data upon request? Are there any additional costs to delete customer data?
Our application is self-serve, allowing application admin to delete or archive customer data. Additionally, our support team can assist with specific issues.
When a customer contract terminates, how long is customer data retained? Can customers retrieve their data regardless of the cause of termination or expiration of agreement?
Upon termination we will provide a data file with all customer data on the termination date. Customer data will be provided regardless of the reason for termination
What options are available for customers to extract their data and in what format?
Data is available via a REST API that customers can access to retrieve data as needed.
Can customers access their backups or request a restore from backup? Are there any extra costs for this?
We can’t provide or restore a particular backup for a client as backups are general for a multi-tenant system. We can provide a stand-alone system for an additional cost.
For Single Sign On, does the application support the following protocols: a. SAML 2.0 b. WS-Trust/WS-Federations c. OAuth
Single Sign On – SAML 2.0
Do you support two factor or multi-factor authentication? If so, provide details.
No.
How is access granted to administrators and users of the cloud service? What type of strong authentication is used? Is there an administrative interface provided to manage the service? Are only authorized users able to change content?
All access to user data is managed by session authorization, users are required to set up a password (10 character minimum) and use it along with their email to access the application. The system is responsible for authorizing the user to access the data. Sessions expire after 30 days and users are required to re-enter their login details.
First user created is granted admin rights of the account and this user can add or remove new users as well as to grant them admin permissions as well
Only admin users can change the general settings of the account or invite new users.
What auditing capabilities exist? (e.g. Access audit, failed access attempts, audit trails of all activity, etc.). Are audits available to administrators or must they be requested from the vendor.
Application tracks changes done to most records, currently there’s no public access to these changes and should be requested
Users with more than 5 failed attempts to login will be blocked and requested to unlock their account via E-mail.
Do you meet the WCAG 2.0 guidelines?
All data is hosted by GCP.