Skip to main content

INFORMATION PROTECTION AND SECURITY STANDARDS

INFORMATION PROTECTION AND SECURITY STANDARDS

 

Physical Security

The Forma Cloud Services relies on AWS who is responsible, in accordance with the AWS Shared Responsibility
Model (available at https://aws.amazon.com/compliance/shared-responsibility-model), for implementing controls for
the physical security of data center facilities, backup media, and other physical systems, providing comprehensive and
state-of-the-art security capabilities (available at https://aws.amazon.com/compliance/data-center/controls).

Forma Farm ensures that such physical security controls provided by AWS for its data center include:

  • Access is restricted by using an electronic key card and/or biometric system, which is unique to each individual.
  • CCTV is present on all access and exit doors, and recordings are stored for at least thirty 30 days.
  • Access areas to the building are guarded by security on a 24/7 basis, 365 days a year, either by internal or externalstaff. An intruder alarm is in place for all building access points to detect and alert against unauthorized entry.
  • Access to the location of the servers and network components that deliver Services, i.e., servers, dialers, switches,routers, firewalls, etc., are restricted to authorized personnel only and adequately logged.

Backup

Backup Policies

Daily Backup
    Automatically runs at 5:00 AM UTC Retention: 7 days
    Weekly Backup
      Automatically runs on Saturdays at 5:00 AM UTC Retention: 4 months (120 days)
      Monthly Backup
        Automatically runs on the first Saturday of the month at 5:00 AM UTC Retention: 3 years (1095 days)
        Backup Status
          Last 30 daily backups: All successfully completed (latest: 11/14/2025 at 6:00 AM) Active monitoring with automatic notifications in case of failure 58 Aurora snapshots available for the db-1-aurora database 180 total recovery points available on AWS Backup

          Access Control

            Backup access limited via specific IAM roles MFA required for critical operations Service Role: AWSBackupDefaultServiceRole with minimal permissions Full audit trail on AWS CloudTrail

            Data Encryption

            Encryption at Rest
              Algorithm: AES-256 via AWS Key Management Service (KMS) Encryption enabled by default on all Aurora databases Snapshots automatically encrypted with the same key as the source database
              Encryption in Transit
                TLS 1.2+ for all application connections Database connections forced over SSL/TLS Backup transfer managed internally by AWS over an encrypted private network

                Monitoring

                The infrastructure is equipped with the following service monitoring procedures and mechanisms:

                  Server log: All accesses and errors are logged on individual server machines (frontend and database) and load balancer (aggregated across all machines connected for the service). Email pre-alerts when peak thresholds are exceeded (CPU usage, number of DB connections). Uptime Robot: Domain monitoring. If the site is unresponsive, the team is notified via email and internal communication channels (Slack). Automatic application error notification: Any errors generated by application functionality on the server are notified to the support team. Monitoring and multi-channel alert system: The difference between available and utilized resources (CPU and RAM) is continuously monitored. When preset thresholds are exceeded, the system invokes autoscaling and communicates the event via various communication channels to the technical staff.

                  Disaster Recovery