Attri Trust Center
Transparency, security, and policies that guide how we protect your data and deliver our services
Attri Data Processing Agreement
Updated: November 28, 2025
Transparency, security, and policies that guide how we protect your data and deliver our services
Updated: November 28, 2025
This DPA forms a binding legal agreement to reflect the Parties' agreement with regard to the Processing of Personal Data (as such terms are defined below).
WHEREAS, Attri shall provide the services set forth in the Agreement (collectively, the "Services") to Customer, as described in the Agreement; and
WHEREAS, the Parties wish to set forth the arrangements concerning the Processing of Personal Data within the context of the Services and agree to comply with the following provisions with respect to any Personal Data, each acting reasonably and in good faith.
NOW THEREFORE, in consideration of the mutual promises set forth herein and other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged by the Parties, the Parties, intending to be legally bound, agree as follows:
1.1 The headings contained in this DPA are for convenience only and shall not be interpreted to limit or otherwise affect the provisions of this DPA. References to clauses or sections are references to the clauses or sections of this DPA unless otherwise stated. Words used in the singular include the plural and vice versa, as the context may require. Capitalized terms not defined herein shall have the meanings assigned to such terms in the Agreement.
1.2 Definitions:
"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. "Control", for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
"Controller" or "Business" as relevant under applicable Data Protection Laws, means the entity which determines the purposes and means of the Processing of Personal Data or such equivalent term under Data Protection Laws.
"Customer Personal Data" means any Personal Data which is provided to and Processed by Attri on behalf of Customer in order to provide the Services under the Agreement. Customer Personal Data does not include Personal Data that Attri Processes as a Controller separately from its Processing obligations to Customer under the Agreement.
"Data Protection Laws" means all laws and regulations of the European Union, the EEA and their Member States, Switzerland, the United Kingdom, and the United States, each to the extent applicable to the Processing of Personal Data under the Agreement.
"Data Subject" means the identified or identifiable person to whom the Customer Personal Data relates.
"EEA" means the European Economic Area.
"EU Data Protection Law" means the GDPR, and the UK GDPR.
"Extended EEA Country" means a Member State of the EEA, Switzerland or the United Kingdom, and Extended EEA Countries means the foregoing countries collectively.
"Member State(s)" means a country that belongs to the European Union and/or the EEA.
"GDPR" means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
"Personal Data" means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier or such equivalent term under Data Protection Laws.
"Process(ing)" means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"Processor" or "Service Provider," as relevant under applicable Data Protection Laws, means the entity which Processes Personal Data on behalf of the Controller or Business or such equivalent term under Data Protection Laws.
"Standard Contractual Clauses" means the "standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council adopted by the European Commission decision of 4 June 2021" and published under document number C (2021) 3972 available at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914&qid=1689513765256, as may be updated, amended or superseded from time to time.
"Sub-Processor" means any Processor or Service Provider engaged by Attri and/or Attri Affiliate to Process Customer Personal Data.
"Supervisory Authority" means the competent supervisory authority pursuant to the applicable Data Protection Laws.
"Third Country" has the meaning given in Clause 8.2 below.
"UK GDPR" means the GDPR as incorporated into United Kingdom domestic law pursuant to Section 3 of the European Union (Withdrawal) Act 2018 (the "UK GDPR").
"US Privacy Laws" means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act of 2020 along with any associated regulations ("CCPA"); the Virginia Consumer Data Protection Act ("VCDPA"); the Colorado Privacy Act; and any similar U.S. laws governing data privacy and security once effective.
Customer shall, in its use of the Services, Process Customer Personal Data in accordance with the requirements of Data Protection Laws and comply at all times with the obligations applicable to Controllers or Businesses, as applicable. For the avoidance of doubt, Customer's instructions for the Processing of Customer Personal Data shall comply with Data Protection Laws. Customer shall have sole responsibility for the means by which Customer acquired Customer Personal Data. Without limitation, Customer shall comply with any and all transparency-related obligations (including, without limitation, displaying any and all relevant and required privacy notices or policies) and shall have any and all required legal basis in order to collect, Process and transfer to Attri the Customer Personal Data and to authorize the Processing by Attri of the Customer Personal Data which is authorized in this DPA.
3.1 Application. As used in clauses 3 – 9 herein, Customer Personal Data refers to Customer Personal Data that is subject to Data Protection Laws.
3.2 Roles of the Parties. The Parties acknowledge and agree that with regard to the Processing of Customer Personal Data, (i) Customer is the Controller or Business, (ii) Attri is the Processor or Service Provider, and (iii) Attri or its Affiliates may engage Sub-Processors pursuant to the requirements set forth in Clause 6 below.
3.3 Attri and its Affiliates (as applicable) shall Process Customer Personal Data only in accordance with Customer's documented instructions, which are set out in the Agreement, as necessary for the performance of the Services and for the performance of the Agreement and this DPA, unless required to otherwise by any applicable law, court of competent jurisdiction or other Supervisory Authority to which Attri and its Affiliates are subject, in which case, Attri shall inform Customer of the legal requirement before processing, unless that law prohibits such information. Customer agrees that the Agreement is its complete and final instructions to Attri in relation to the Processing of Personal Data. Processing any Personal Data outside the scope of the Agreement will require prior written agreement between Attri and Customer by way of an amendment to the Agreement, and may include any additional fees that may be payable by Customer to Attri for carrying out such instructions. The duration of the Processing, the nature and purposes of the Processing, as well as the types of Customer Personal Data Processed and categories of Data Subjects under this DPA are further specified in Schedule 1 to this DPA.
3.4 To the extent that Attri or its Affiliates cannot comply with an instruction from Customer and/or its authorized users relating to Processing of Customer Personal Data or where Attri considers such instruction to be unlawful, Attri (i) shall inform Customer, providing relevant details of the problem; (ii) may, without any kind of liability towards Customer, temporarily cease all Processing of the affected Customer Personal Data (other than securely storing those data); and (iii) if the Parties do not agree on a resolution to the issue in question and the costs thereof, each Party may, as its sole remedy, terminate the Agreement and this DPA with respect to the affected Processing, and Customer shall pay to Attri all the amounts owed to Attri or due before the date of termination.
If Attri receives a request from a Data Subject to exercise its rights under Data Protection Laws ("Data Subject Request"), Attri shall, to the extent legally permitted, promptly notify and forward such Data Subject Request to Customer. Taking into account the nature of the Processing, Attri shall use commercially reasonable efforts to assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of Customer's obligation to respond to a Data Subject Request under Data Protection Laws.
5.1 Confidentiality. Attri shall grant access to the Customer Personal Data to persons under its authority (including, without limitation, its personnel) only on a need-to-know basis and ensure that such persons engaged in the Processing of Customer Personal Data have committed themselves to confidentiality.
6.1 Customer hereby grants general written authorization to Attri to appoint Sub-Processors to perform specific Processing activities on Customer Personal Data on its behalf. Attri's current list of Sub-Processors has been made available to Customer upon written request to hello@attri.ai ("Sub-Processor List") and is hereby approved by Customer.
6.2 Objection Right for Sub-Processors. Attri offers a mechanism for Customers to subscribe to notifications of changes to Attri's Sub-Processor List via written request to hello@attri.ai. If Customer subscribes to receive such updates, Attri shall provide notification of any intended changes concerning the addition or replacement of other Sub-Processor(s) to the email address which has subscribed thereby giving Customer the opportunity to object. Customer may reasonably object to Attri's use of a Sub-Processor for reasons related to the Data Protection Laws by notifying Attri in writing within ten (10) days after receipt of Attri's notice including the reasons for objecting to Attri's use of such Sub-Processor. Failure to object to such Sub-Processor in writing within ten (10) days following Attri's notice shall be deemed as acceptance of the Sub-Processor. In the event Customer reasonably objects to a Sub-Processor, Attri will use reasonable efforts to make available to Customer a change in the Services to avoid Processing of Customer Personal Data by the objected-to Sub-Processor without unreasonably burdening Customer. If Attri is unable to make available such change within a reasonable period of time, which shall not exceed thirty (30) days, Customer may, as a sole remedy, terminate the Agreement and this DPA by providing written notice to Attri provided that all amounts due under the Agreement before the termination date shall be duly paid to Attri. Until a decision is made regarding the Sub-Processor, Attri may temporarily suspend the Processing of the affected Customer Personal Data.
6.3 Where Attri engages a Sub-Processor, we shall do so by way of a written contract which imposes on the Sub-Processor substantially the same data protection obligations as in this DPA.
7.1 Controls for the Protection of Customer Personal Data. Taking into account the state of the art, Attri shall maintain industry-standard technical and organizational measures, including as required pursuant to Article 32 of the GDPR and other applicable Data Protection Laws, for protection of the security (including protection against unauthorized or unlawful Processing and against accidental or unlawful destruction, loss or alteration or damage, unauthorized disclosure of, or access to, Customer Personal Data), confidentiality and integrity of Customer Personal Data, as set forth in the Security Addendum. Upon Customer's request, Attri will use commercially reasonable efforts to assist Customer, in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR and other applicable Data Protection Laws taking into account the nature of the processing, the state of the art, the costs of implementation, the scope, the context, the purposes of the Processing and the information available to Attri.
7.2 Third-Party Certifications and Audits. Upon Customer's written request at reasonable intervals, and subject to the confidentiality obligations set forth in the Agreement, Attri shall make available to Customer (or Customer's independent, third-party auditor that is not reasonably objected to by Attri and bound by confidentiality obligations) a copy of Attri's then most recent third-party audits or certifications, as applicable (provided, however, that any such documentation shall be Attri's confidential information and shall only be used by Customer to assess compliance with this DPA, and shall not be used for any other purpose or disclosed to any third party without Attri's prior written approval and, upon Attri's request, Customer shall return all such documentation in Customer's possession or control). Only as required by applicable Data Protection Laws and at Customer's cost and expense, not more than once per year, Attri shall allow for and contribute to audits, including remote inspections, conducted by Customer (or Customer's independent, third-party auditor that is not reasonably objected to by Attri and that is bound by confidentiality obligations) provided that the parties shall agree on the scope, methodology, timing and conditions of such audits and inspections in advance. Notwithstanding anything to the contrary, such audits and/or inspections shall not contain any information, including without limitation, Personal Data that belongs to Attri's other customers.
8.1 Transfers to countries that offer adequate level of data protection. Personal Data may be transferred from the Extended EEA Countries to countries or frameworks that offer adequate level of data protection under or pursuant to the adequacy decisions published by the relevant data protection authorities of the Extended EEA Countries ("Adequacy Decisions"), without any further safeguard being necessary.
8.2 Transfers to other countries. If, and to the extent, the Processing of Customer Personal Data which is subject to Data Protection Laws of the Extended EEA Countries includes transfers by Customer from the Extended EEA Countries to Attri in countries outside the Extended EEA Countries which have not been subject to an Adequacy Decision ("Third Countries"), the Parties agree that such transfers shall be undertaken on the basis of the Standard Contractual Clauses, which will be deemed to have been signed by each Party on the Effective Date of this Agreement, are incorporated herein by reference and construed in accordance with Schedule 2 below, unless another mechanism provided for in the Data Protection Laws of the applicable Extended EEA Country applies.
8.3 In the event Customer enables Third Party Integrations (as defined in the Agreement) which involve transfers of Customer Personal Data between Attri and the Third Party Integration provider, Customer acknowledges and agrees that (a) such Third Party Integration providers are not Sub-Processors of Attri; (b) such transfers are conducted at Customer's instruction in accordance with an agreement between the Customer and such Third Party Integration provider (which Attri is not a party to); and (c) Customer shall be solely responsible for such transfers and their compliance with Data Protection Laws, including without limitation, executing Standard Contractual Clauses with such Third Party Integration providers as required.
9.1 In performing its obligations under the Agreement and this DPA, Attri will not: (1) "sell" or "share" for purposes of "cross-context behavioral advertising" or "targeted advertising" (as defined by applicable US Privacy Laws) any Customer Personal Data; (2) retain, use, or disclose Customer Personal Data outside of the direct business relationship between Attri and Customer; or (3) attempt to re-identify any pseudonymized, anonymized, aggregate, or de-identified Customer Personal Data.
9.2 Attri will (1) comply with any applicable restrictions under applicable US Privacy Laws on combining Customer Personal Data with Personal Data that Attri receives from, or on behalf of, another person or persons; and (2) promptly notify Customer if Attri determines that it (i) can no longer meet its obligations under this DPA or applicable US Privacy Laws; or (ii) in Attri's opinion, an instruction from Customer infringes applicable US Privacy Laws.
9.3 To the extent required under US Privacy Laws, Customer may take reasonable and appropriate steps to help to ensure that Attri uses Customer Personal Data in a manner consistent with Customer's obligations under US Privacy Laws and to stop and remediate unauthorized use of the Customer Personal Data.
9.4 Attri certifies that it understands its obligations in this Clause 9. The Parties agree that Schedule 1 hereto shall satisfy any requirement under applicable U.S. Privacy Law to provide details regarding the nature of the Processing activities related to Customer Personal Data.
To the extent required under applicable Data Protection Laws, Attri shall notify Customer without undue delay after becoming aware of the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (a "Personal Data Incident"). Attri shall make reasonable efforts to identify the cause of such Personal Data Incident and take those steps as Attri deems necessary, possible and reasonable in order to remediate the cause of such a Personal Data Incident. Customer (or its customers), as the Controller or Business, will be the party responsible for notifying supervisory authorities and/or concerned Data Subjects (where required by Data Protection Laws).
Subject to the Agreement, upon termination or expiry of the Services, Attri shall, make available for return the Customer Personal Data via the Services and delete such Customer Personal Data in accordance with Attri's customer data retention & deletion policy unless applicable law requires storage of the Customer Personal Data. In any event, Customer agrees that Attri may retain Customer Personal Data in accordance with its standard backup policy, for evidence purposes and/or for the establishment, exercise or defence of legal claims and/or to comply with applicable laws and regulations. Notwithstanding anything to the contrary, Customer hereby agrees and understands that, to the extent Attri performs cloud scanning on behalf of Customer, if and when Customer wants to delete specific Customer Personal Data, Customer may delete such Customer Personal Data from its own databases, and it will automatically be erased from Attri's databases within a reasonable market standard timeframe. If Customer requests return of the Customer Personal Data, it shall be returned in an industry standard format generally available for Attri's Customers.
This DPA shall automatically terminate upon the termination or expiration of the Agreement under which the Services are provided, provided that, to the extent Attri retains any Customer Personal Data following termination or expiration of the Agreement, this DPA shall survive for such period that Attri retains Customer Personal Data. Clauses 2, 3.4 and 13 shall survive the termination or expiration of this DPA for any reason. This DPA cannot, in principle, be terminated separately to the Agreement, except where the Processing ends before the termination of the Agreement, in which case, this DPA shall automatically terminate.
Subject to any provisions in Schedule 2 regarding governing law and choice of forum of the Standard Contractual Clauses, the governing law and choice of forum provision in the Agreement shall apply to this DPA. In the event of any conflict between the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA shall prevail over the conflicting provisions of the Agreement.
Any Attri obligation hereunder may be performed (in whole or in part), and any Attri right (including invoice and payment rights) or remedy may be exercised (in whole or in part), by an Affiliate of Attri.
Attri will Process Customer Personal Data as necessary to perform the Services pursuant to the Agreement, as further instructed by Customer in its use of the Services.
Subject to any section of the DPA and/or the Agreement dealing with the duration of the Processing and the consequences of the expiration or termination thereof, Attri will Process Customer Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing.
Customer determines the categories of any Customer Personal Data that is made accessible to Attri, which may include, without limitation, Customer Personal Data relating to the following categories:
If Customer uses Attri for scanning, Personal Data might be temporarily processed by Attri during the scanning. The type of the Personal Data depends on Customer environment and which sources Customer connects.
Attri only stores metadata such as CVEs, misconfigurations, list of installed packages, cloud events, local cloud user accounts, cloud object identifiers and (depending on the features used by Customer) logs and file paths. Such metadata does not generally contain Personal Data, however, depending on the Customer's environment and naming conventions and the features used by Customer, some limited Personal Data may be included. For example, cloud user account names, logs and artifacts could include an individual's name, logs could contain names, associated email address and IP address and (if specific Attri features are enabled) pseudonymized samples of findings to enable Customer to locate, verify and remediate the finding(s).
Customer acknowledges that Attri does not control which Customer Personal Data Customer shares with it in the context of the Services.
As part of providing the Services, Attri may process Customer Personal Data related to Customer's customers or users, leads, employees and service providers, the extent of which is solely determined by Customer.
1.1 In relation to transfers by Customer of Customer Personal Data which are subject to Data Protection Laws of the Extended EEA Countries to Attri in Third Countries, the parties agree that Module Two (Transfer controller to processor) or Module 3 (Transfer processor to processor) of the Standard Contractual Clauses shall apply, as applicable.
1.2 The Parties acknowledge that the information required to be provided in the Standard Contractual Clauses, including the appendices, is set out in Appendix 1 below.
1.3 If there is a conflict between the provisions of this Agreement and the Standard Contractual Clauses, the Standard Contractual Clauses will prevail, provided that, except to the extent prohibited by applicable law, the Standard Contractual Clauses shall be interpreted in accordance with and subject to this DPA and the Agreement, including without limitation, the provisions on limitation of liability, instructions, storage, erasure and return of Personal Data, audits and engagement of Sub-Processors.
1.4 If any provision or part-provision of this DPA or the Agreement causes the Standard Contractual Clauses to become an invalid export mechanism in the relevant Extended EEA Country, it shall be deemed deleted but that shall not affect the validity and enforceability of the rest of this Agreement and the parties shall negotiate in good faith to agree a replacement provision that, to the greatest extent possible, achieves the intended commercial result of the original provision.
1.5 Where requested by Attri, Customer shall provide reasonable assistance to Attri and be responsible for issuing such communications to Data Subjects and/or the Controller (to the extent Module Three applies) as are required in order for Attri to comply with its obligations under the Standard Contractual Clauses.
1.6 For the purpose of Section III, Clause 14 of the Standard Contractual Clauses, the parties acknowledge and agree that, as between the parties, the Customer (acting as data exporter) is responsible for: (i) assessing the laws of the country to which it transfers Personal Data; and (ii) determining whether or not the transfer meets the requirements of Section III, Clause 14(a) of the Standard Contractual Clauses. Where Attri (as data importer) provides information to the Customer (acting as data exporter) for assisting the Customer in its assessment, such information is provided on an "as is" basis for informational purposes only. Without prejudice to Section III, Clause 14(c) of the Standard Contractual Clauses, Attri (as data importer) shall not be liable for any losses suffered by the Customer in connection with its assessment.
1.7 Notwithstanding anything to the contrary, where the applicable Extended EEA Country where the data exporter is established or from where the transferred personal data originated is the UK, template Addendum B.1.0 issued by the UK ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses, (the "UK Approved Addendum") shall amend the Standard Contractual Clauses in respect of such transfers and Part 1 of the UK Approved Addendum shall be populated as set out below:
Table 1. The "start date" will be the date this DPA enters into force. The "Parties" are Customer as exporter Attri as importer.
Table 2. The "Addendum EU SCCs" are the modules and clauses of the Standard Contractual Clauses selected in relation to a particular transfer in accordance with paragraphs 1.1 and 1.2 of this Schedule.
Table 3. The "Appendix Information" is as set out in Appendix 1 to this Schedule.
Table 4. Neither party may end the UK Approved Addendum in accordance with its Section 19.
1.8 Except where paragraph 1.9 above applies, but notwithstanding anything else to the contrary, where the applicable Extended EEA Country where the data exporter is established or from where the transferred personal data originated is not a Member State of the European Union, references in the Standard Contractual Clauses to:
(a) "Member States of the European Union" shall refer to the applicable Extended EEA Country in which the data exporter is established or from where the transferred Personal Data originated (as applicable);
(b) "the GDPR" shall refer to the Data Protection Laws of the Extended EEA Country in which the data exporter is established or from where the Personal Data originated; and
(c) "supervisory authority" shall refer to the data protection authority in the Extended EEA Country as determined in Annex I(C) below.
Data Exporter:
Data Importer:
| Item | Description |
|---|---|
| CATEGORIES OF DATA SUBJECTS | As described in Schedule 1 |
| CATEGORIES OF PERSONAL DATA | As described in Schedule 1 |
| SPECIAL CATEGORIES OF DATA (IF APPLICABLE) | Attri does not control which Personal Data Customer shares with it in the context of the Services |
| FREQUENCY OF THE TRANSFER | As regular as is required to provide the Services |
| NATURE AND PURPOSE OF THE PROCESSING | As described in Schedule 1 |
| RETENTION | As described in Schedule 1 |
| TRANSFER TO (SUB)PROCESSORS | As set out in Attri's Sub-Processor List |
The competent supervisory authority shall be determined in accordance with Clause 13 of the Standard Contractual Clauses.
Where an EU Representative has not been appointed by data exporter, the competent supervisory authority shall be the supervisory authority of the Netherlands.
GOVERNING LAW
For the purposes of Clause 17 of the Standard Contractual Clauses the Parties select OPTION 1: the law of the Netherlands.
CHOICE OF FORUM
For the purposes of Clause 18 of the SCCs: the Parties select the courts of the Netherlands.
Where the Standard Contractual Clauses identify optional provisions (or provisions with multiple options) the following will apply:
The technical and organizational measures including technical and organizational measures to support the security of Personal Data incorporated into Annex II of the Standard Contractual Clauses shall be the technical and organizational security measures as described in the Security Addendum.
In addition, Attri agrees to the following compensating safeguards to protect such data to an equivalent level as required under the Data Protection Laws of the Extended EEA Countries to the extent required under the Standard Contractual Clauses:
Attri has implemented a comprehensive security, compliance and privacy management program under which Attri maintains industry standard physical, administrative, organizational and technical safeguards designed to protect the confidentiality, integrity, availability, and security of the Services and Customer Data, including the measures set forth herein (the "Security Program"). Attri regularly tests and evaluates its Security Program and may review and update its Security Program as well as this Attri Security Addendum from time to time including to take in account technological developments, provided, however, that such updates shall be designed to enhance and not materially diminish the Security Program.
IaaS Provider. Attri's Platform is hosted on AWS.
Hosting location. Attri offers hosting in several locations including in the US, the EU and the UK. Customer may select the region in which their Attri tenant will be hosted prior to the tenant being created.
Certifications. Attri shall be assessed by independent third-party auditors on at least an annual basis under the following audits and certifications ("Third Party Certifications"): SOC2 Type 2, SOC3, ISO 27001, ISO 27701, ISO 27017 and/or ISO 27018. Attri shall make available to Customer such Third-Party Certifications upon Customer's written request. To the extent Attri decides to discontinue a Third-Party Certification, Attri will adopt or maintain an equivalent, industry-recognized framework or standard.
PCI-DSS. To the extent Attri processes cardholder data in the provision of Services, Attri shall perform a Payment Card Industry Data Security Standard Attestation of Compliance ("AOC") for Service Providers on an annual basis and shall provide such AOC to Customer upon Customer's written request.
Encryption of Customer Data. Customer Data shall be encrypted by Attri in transit (TLS 1.2. or above) and at rest (AES 256).
Key Management. Attri utilizes AWS' Key Management System (KMS) to encrypt Customer Data. Keys are rotated periodically and are stored only in the KMS in the region of the Customer's Attri tenant.
User Authentication (Attri Employees). Attri enforces user authentication and authorization on Attri systems via Single Sign-on ("SSO") and multifactor authentication ("MFA").
User Authentication (Customer using Attri). Attri supports SAML 2.0 compliant SSO applications, allowing customers to manage authentication for their own Attri tenant.
Secure Storage of Credentials. Attri uses managed authentication services (Okta for Attri's employee environment; Amazon Cognito for Attri's software platform) to handle authentication and associated credential management, including encryption in-motion and at-rest for passwords and other forms of credentials. Cloud-native Key Management Systems, such as AWS KMS, are used to store other forms of access tokens and secrets.
Role-based Access Control (RBAC) for Attri Employees. Access to Attri information assets is restricted, and is granted to Attri employees and contractors in order to fulfill their duties on a need-to-use basis and following the least privilege principle. Attri employees and contractors are not granted access to any information asset that is not required by their work at Attri. Attri has defined various user roles, according to the positions and activities in the company. Each Attri employee and contractor is assigned one of these roles and receives access control privileges relevant to that role. Quarterly reviews for user access will be conducted and access will be immediately revoked for unrequired access.
Role-based Access Control for Customers using Attri. Attri provides customers with the ability to define roles for their own Attri users that control the information they see and the actions they perform.
Access to Customer Data. Attri personnel will not access Customer Data except (i) as reasonably necessary to provide the Attri Services under the Agreement; (ii) with Customer's permission; or (ii) to comply with the law or a binding order of a governmental body.
Minimum password requirements. Attri shall follow the guidance provided by NIST 800-63B Digital Identity Guidelines to enforce password security controls, including length, complexity, re-use, lock-out, and use of multi-factor authentication. Passwords must never be stored in plain-text nor transmitted over unencrypted channels.
Session lifespan. Single-sign on sessions expire after 8 hours of inactivity with a maximum duration of 12 hours.
Session Lock out. End-user devices are set to screen lock and require a password after 15 minutes of inactivity.
Workstation Security Controls. For access to Attri systems, Attri personnel must use Attri-issued laptops which utilize security controls that include, but are not limited to, (i) disk encryption, (ii) endpoint firewall, (iii) anti-malware and endpoint detection and response (EDR) tools, and (iv) vulnerability management tools in accordance with Section 9.1 (Vulnerability & Detection Management).
Anti-malware. Attri maintains anti-malware controls to automatically detect and prevent malicious files, user activity, and network activity on Attri workstations, within Attri's e-mail, and within Attri's corporate cloud storage solutions.
Workstation Management and Hardening. Attri utilizes system management technologies to ensure that all endpoints are appropriately configured, hardened, and patched following Attri's technical procedures and applicable industry standards such as CIS Benchmarks.
Data Loss Prevention. Attri utilizes Data Loss Prevention (DLP) technologies to monitor and control sensitive information that is stored or accessed on systems. Attri workstations are restricted from using removable storage devices and media.
Separation of Environments. Attri's cloud network is divided into three segregated network environments: The development network, the staging network, and the production network. Each of these environments is segregated from the others and has its own privilege allocation and access control. There is no shared network, communication, or co-operation between the networks. Customer Data is never stored or accessed in development environments.
Infrastructure as Code. Attri's cloud production environments are configured, provisioned, and managed through Infrastructure as Code (IaC), and subject to the controls defined in Attri's Software Development Lifecycle (SDLC).
Remote Access. Attri enforces device, network, authentication, and resource-specific authorization controls to limit access to development and production environments. Attri does not automatically confer privileged access to any workstations or devices based on location.
Network Security. Attri utilizes cloud-native network security technologies, including network security groups, Web Application Firewalls, access gateways, application load balancers, and VPC configurations, to restrict ingress and egress traffic in cloud environments to the minimum sets of services and addresses required for business functionality.
Cloud Infrastructure Hardening. Attri utilizes its own instance of the Platform ("Attri for Attri") in conjunction with cloud-native security services to ensure that cloud resources are configured and secured in accordance with Attri's internal technical procedures and industry standards such as the CIS AWS benchmarks.
Anti-malware. Attri utilizes Attri for Attri in conjunction with cloud-native security services to detect and respond to potentially malicious activity on its cloud-hosted workloads or networks.
Logging. Attri maintains security auditing and logging capabilities for the infrastructure, SaaS applications, and cloud services that support its corporate, development, and production environments in accordance with Attri's Information Security Policies. The use and activity of Attri information assets is logged and audited for suspicious activity. Attri preserves security-related logs for a minimum of 12 months unless otherwise specified in its security policies and procedures.
Detection and Response Operations. Attri uses Security Information Event Management (SIEM), Detection, and Alert Notification technologies to centralize and analyze logs, apply detection criteria, and escalate and route events to the appropriate security teams.
Customer Access to Logs. Customers have access to system and user activity logs for their respective Attri tenant via the Platform, and can export these logs to their own log storage or SIEM platforms as described in the Documentation.
SDLC. Software development in Attri is performed according to Attri's Change Management & Software Development Life Cycle (SDLC) procedures.
Security Reviews. Attri conducts security reviews for significant changes, such as major new product features or changes that impact Attri's security posture, during the design and development process.
Peer Reviews. Code changes must undergo secondary review and approval before being promoted to production.
Security Testing within the SDLC. Attri uses security technologies to automatically scan for vulnerabilities, exposed secrets, and code security risks as part of the CI/CD pipeline.
Vulnerability Detection & Management. Attri shall maintain a continuous vulnerability management process across its corporate and production environments to ensure that vulnerabilities and other threats are quickly identified, prioritized, and remediated. This includes carrying out internal vulnerability tests daily and external vulnerability tests regularly (at least quarterly). Vulnerabilities shall be remediated according to Attri's Vulnerability Management Policy which shall meet or exceed industry standards. Attri uses the Common Vulnerability Scoring System (CVSS) v3.1 and National Vulnerability Database (NVD) ratings as guidelines for patch prioritization and scheduling.
Penetration Testing. Attri shall engage one or more independent third parties to conduct penetration tests of the Service at least annually and upon major changes to the Services. Attri will provide summary results of penetration tests to Customer upon written request.
Personnel Security. All prospective Attri employees go through pre-employment reference and/or background checks, according to the local HR policies and applicable laws.
Personnel Agreements. All Attri employees and contractors are required to sign a contract which includes a confidentiality obligation and are provided with Attri's security policies, including Attri's Acceptable Use Policy, when their work commences. Any change in an employee's position in Attri or change in his or her access privileges immediately affects the employee's access via the centralized access control system.
Personnel Training. All Attri employees are required to complete security and privacy awareness training during onboarding and on at least an annual basis.
Attri Risk Management. Attri maintains a third-party Attri risk management program, which includes a compliance, security, and privacy review for every third-party used in the provision of the Services and/or with access to Customer Data. The results of the risk assessment are reviewed by the security, legal and privacy team to ensure the third party maintains security measures consistent with the measures hereunder.
Cloud Environment Data Centers. Attri only utilizes leading cloud providers who shall be required to have a SOC 2 Type II annual audit and ISO 27001 certification, or industry recognized equivalent frameworks.
Attri Corporate Offices. Attri's employees and subcontractors in each of Attri's offices are subject to Attri's physical minimum-security requirements which include use of CCTV with a defined retention period in accordance with applicable laws, badge only access with regular access reviews and requirements for visitors to be logged and accompanied by Attri authorized personnel.
Attri shall maintain a formal documented Information Security Incident Management Program designed to provide an effective and consistent process for managing security incidents.
Security Incident notification. In any event of a reasonably suspected or successful unauthorized access, use, disclosure, modification, or destruction of Customer Data ("Security Incident"), Attri will notify Customer within 48 hours of becoming aware of the Security Incident and shall promptly take reasonable steps to contain, investigate, and mitigate such Security Incident. Attri shall provide Customer with assistance and information as reasonably required by Customer in order to fulfil its legal obligations.
Security Incident Reporting and Response. Security Incidents are reported to Attri's Chief Information Security Officer (CISO). The CISO acts according to Attri's Incident Response Plan in classifying, handling, documenting, and reporting any incident. Customer may request a copy of Attri's Incident Response Plan.
Business Continuity and Disaster Recovery Plan. Attri maintains industry standard business continuity and disaster recovery procedures, as further described in Attri's Business Continuity and Disaster Recovery Plan ("BCDRP"), and will implement these procedures to minimize the impact of events, whether related to technology or operational failures, that may affect Attri's ability to provide the Services. Attri shall provide Customer with its BCDRP upon Customer's written request. Attri's RTO shall not exceed 48 hours.
Testing of BCDRP. Attri shall conduct testing of its BCDRP at least annually and shall make the results of such testing available to Customer upon written request.
Backups and Disaster Recovery. Attri leverages multiple Amazon services to backup Customer Data on both daily and monthly schedules. Each Customer tenant is allocated a disaster recovery tenant in a geographically distinct area. Where possible, Attri will use a disaster recovery region in the same jurisdiction as the main data center. Attri also keeps full and incremental backups of critical corporate data and logs in geographically distinct datacenters.
To the greatest extent possible, Customer shall utilize Attri's Third-Party Certifications and other security documentation and policies to assess Attri's compliance with its obligations hereunder. Only to the extent that Customer is not able to do so, and in any event, no more than once per year except if required by applicable law, and following at least 45 days' notice in writing from Customer, Attri shall provide Customer (and/or Customer's third party advisors who are not reasonably objected to by Attri and who are subject to appropriate confidentiality obligations) with access to documents, systems, Attri employees and electronic data as reasonably necessary in order to audit Attri's compliance with its obligations under this Addendum. Attri shall provide assistance, co-operation, and access reasonably required by Customer in relation to the conduct of such audits. Customer shall use reasonable endeavors to ensure that the conduct of each audit does not disrupt the Attri's business. In no event shall Customer be permitted to access to any information, including without limitation, personal data that belongs to Attri's other customers or such other information that is not relevant to Attri's compliance with this Addendum. Except as required by law, the Parties shall agree on the scope, methodology, timing and conditions of such audits in advance.
Without derogating from Attri's obligations hereunder, Customer acknowledges that it is responsible for implementing, running and managing the Platform on a day-to-day basis. In addition, Customer acknowledges and agrees that it has obligations with respect to the security of the Customer Data and the Services. Customer's responsibility includes but is not limited to: (i) the security of cloud environments it owns, operates, and connects to Attri, and for configuration of its instance(s) of the Attri Platform; (ii) provisioning Permitted Users with access to Customer's instance of the Attri Platform, including: (a) managing instance-level administrators and other user privileges; (b) deauthorizing Permitted Users who no longer need access; (c) provisioning and configuring service account or API access; (d) enabling integrations with customer-owned or third-party technologies; and (e) ensuring that all Permitted User's keep all Attri credential's confidential; and (iii) updating any Attri provided software upon Attri's announcement of such updates. Attri provides customers with audit logs that record customer user account and application activity occurring within their respective Attri Platform instance(s), however, Customer is responsible for monitoring its own instance's audit logs for security or other purposes. Customer agrees to notify Attri upon becoming aware of any reasonably suspected unauthorized access to the Platform.