Our Security
edays uses outstanding technology and processes to safeguard our customers’ data in line with global compliance.
You trust us to keep your employees’ data safe – which is exactly what we do
Application development
edays uses an agile development methodology with 2-week sprints involving regular backlog refinement meetings, sprint planning meetings, and a sprint review and retrospective at the end. Testing is performed within the sprint, so code updates and developments can be released regularly.
Access control
edays uses a roles-based access control system throughout all aspects of the company. Using a combination of Active Directory and Azure Active Directory to enable permissions for users throughout the organisation, which allows us to control access to sensitive data.
Encryption
edays utilises a range of cryptographic controls to keep your data secure. Encryption is used throughout edays, both for data at rest and data encryption in transit.
Employee screening
Employees working in roles that have access to sensitive data are required to undergo a credit and criminal records check. This will be undertaken before the employee starts in the role, but edays reserves the right to re-check individuals over the course of their employment.
ISO27001
At edays, the security of our customers data is a top priority and on 5th November 2019 edays was issued the certificate to confirm the company’s compliance with the ISO 27001 standard. ISO 27001 is the international standard that helps businesses to manage their information security in line with industry-recognised best practices.
Hosting provider
edays chose Microsoft to host the edays application due to its commitment to security and compliance offerings. Microsoft has an extensive number of certifications which you can view below. If you would like more information on Microsoft’s compliance offerings, you can visit their website.
Penetration testing & vulnerability scanning
Application security is crucial to keep customer data secure. That is why edays conducts annual third-party penetration testing and weekly vulnerability scans to make sure that edays’ code is secured against the latest threats.
FREQUENTLY ASKED QUESTIONS