System Security, Performance and Reliability StatementSurveyShack’s online survey systems are housed in a state-of-the-art data centre on the main backbone of the Internet. Strategically located, the data centre has multiple, redundant Internet carriers, backup power facilities, security and more.
Our applications run 24 hours per day and are monitored by experienced engineers. All of this ensures that the applications are always ready when you are, and working, even when you're not. Should any security issue be identified, SurveyShack has the ability to immediately disable, or shut down parts or all of the application online. Automated monitoring & correction systems are in use 24/7 and IT staff are alerted by email, pager and text when resolution requires intervention. SecurityPhysical SecurityThe SurveyShack server farm is hosted with a leading UK host in a locked cage-type environment where access to the server is restricted by secure appointment and photo ID security card access.Network SecurityAll network components and servers are monitored 24 hours a day, 7 days a week by qualified network engineers which means that reaction times to issues are as fast as they possibly can be.The network is appropriately protected by fire-walling technology and all SurveyShack members have the ability to choose to have all traffic to our server authenticated by cryptographic technology by means of SSL with 128 bit encryption (High); RSA with 1024 bit exchange. Host SecurityHosting is on a Unix platform which has been hardened against attack by the following means:
Web SecurityThe SurveyShack.com application is written in a combination of ModPerl and Javascript and data is stored and managed in a secure and robust Sybase database.Scripts can only be run outside the web root, data in the database is stored in an encrypted format, and is protected by a strong password which conforms to our password rules above. SurveyShack.com undertakes the following security Quality Assurance testing for the application on a monthly basis:
Intrusion protectionIntrusion detection systems automatically protect against attacks and all other suspicious activities.Traffic is automatically blocked from any sources that show unusual behaviour patterns or exceed certain thresholds. All suspicious events are logged and IT staff notified. Multiple levels of firewall control are in place. Performance and ReliabilitySecurity is only one aspect of the robustness of a system. The most secure server is of no use if it's inaccessible half the time or too slow. SurveyShack treats reliability equally as important as security, both of which are always a top priority and are constantly monitored.
SurveyShack’s farm of servers are managed by redundant load balancing front-end routers which distribute traffic across the farm to ensure that no server is overloaded.
The basic architecture includes:
Electrical PowerPower to the servers are routed through lightning protection, a generator able to power the entire server centre and redundant UPS’s before getting to the servers. This ensures that all power to the servers is supplied at a smooth rate and also ensures that sufficient and clean power can be maintained for an indefinite period of time even in an extended power failure.Fire ProtectionThe server room is air tight, kept clean and cool to minimise the risk of fire.
A state of the art Fire Suppression System is in place and should a fire break out in the server room, gas is released to distinguish the fire. The gas is heavier than oxygen and therefore displaces it from the room and extinguishes the fire within seconds. System and Data Back-UpSurveyShack maintains multiple back ups of all code, html and databases. The first level of backup is in the form of RAID disk sets for immediate protection. The second level of backup is in the form of 3 sets of copies of all files and database data, one on-site and 2 off-site (one in a different country). At the worst case, disaster recovery will take up to 1 hour to re-build all systems in a different location to our main hosting solution. At best case, restoration is immediate without any downtime.
System UpgradesThe SurveyShack system is under constant development and all upgrades and enhancements are instantly available to all users once deployed. This is provided at no extra cost to users as part of the annual service charge and means no effort is required by users to ensure they always have access to the latest features and most up-to-date system. Any system improvements and added features/functionality are uploaded and described in the online user manual at the time of deployment.
UptimeSurveyShack has multiple instances of all systems which means that if one system has an issue, the backup system will come online to allow engineers ample time to fix whatever issues may have occurred. Our industry standard 99.6% guaranteed uptime has always been achieved and currently sits at 99.9%. Our systems have in-built monitoring to alert engineers immediately when any of our systems go offline at which point up to 3 engineers will be sent an alert by text and email to alert time of the issue. With 24/7 monitoring in this way, we rarely have any downtime. Any issues are covered by backup systems allowing ample time for rectification while customers experience the minimum possible downtime, if any at all.
System and User SupportAll technical support requests, whether received by email or telephone, are attended to immediately by SurveyShack’s helpline support staff. In the rare event that they are unable to meet the client’s needs, the issue is immediately referred to the technical support team who attend to all client-based enquiries as a matter of first priority. Where necessary, they may liaise directly with the customer to ensure the most efficient communication is achieved and the matter resolved in the shortest possible timeframe. Ownership of DataAll data acquired by the system remains the exclusive property of The Client and is available to The Client at any time. Quality / Professional BodiesSurveyShack is a registered Data Controller under the Data Protection Act 1998 and as such is legally bound to meeting all requirements, as defined by the Act. SurveyShack is also a fully paid up Company Partner Membership of the MRS (the Market Research Society www.mrs.org.uk) and as such is bound by the MRS code of ethics.
The Bottom LineThe bottom line is that SurveyShack are serious about security and reliability. We realize that there are no excuses and no shortcuts when it comes to these two issues.
We see this as a continual, daily process to monitor and change with new threats and issues relating to security and reliability to ensure the long term relationships we desire with all of our clients. If you have any questions or comments about security or reliability, please contact us
|
Security and Reliability


