INFORMATION PROTECTION AND SECURITY STANDARDS
INFORMATION PROTECTION AND SECURITY STANDARDS
Physical Security
The Forma Cloud Services relies on AWS who is responsible, in accordance with the AWS Shared Responsibility
Model (available at https://aws.amazon.com/compliance/shared-responsibility-model), for implementing controls for
the physical security of data center facilities, backup media, and other physical systems, providing comprehensive and
state-of-the-art security capabilities (available at https://aws.amazon.com/compliance/data-center/controls).
Forma Farm ensures that such physical security controls provided by AWS for its data center include:
- Access is restricted by using an electronic key card and/or biometric system, which is unique to each individual.
- CCTV is present on all access and exit doors, and recordings are stored for at least thirty 30 days.
- Access areas to the building are guarded by security on a 24/7 basis, 365 days a year, either by internal or externalstaff. An intruder alarm is in place for all building access points to detect and alert against unauthorized entry.
- Access to the location of the servers and network components that deliver Services, i.e., servers, dialers, switches,routers, firewalls, etc., are restricted to authorized personnel only and adequately logged.
Backup
Backup Policies
Daily Backup
- Automatically runs at 5:00 AM UTC
- Retention: 7 days
Weekly Backup
- Automatically runs on Saturdays at 5:00 AM UTC
- Retention: 4 months (120 days)
Monthly Backup
- Automatically runs on the first Saturday of the month at 5:00 AM UTC
- Retention: 3 years (1095 days)
Backup Status
- Last 30 daily backups: All successfully completed (latest: 11/14/2025 at 6:00 AM)
- Active monitoring with automatic notifications in case of failure
- 58 Aurora snapshots available for the db-1-aurora database
- 180 total recovery points available on AWS Backup
Access Control
- Backup access limited via specific IAM roles
- MFA required for critical operations
- Service Role: AWSBackupDefaultServiceRole with minimal permissions
- Full audit trail on AWS CloudTrail
Data storage and Localization
Geographic Location
Redundancy
Backup Vault
Data Encryption
Encryption at Rest
- Algorithm: AES-256 via AWS Key Management Service (KMS)
- Encryption enabled by default on all Aurora databases
- Snapshots automatically encrypted with the same key as the source database
Encryption in Transit
- TLS 1.2+ for all application connections
- Database connections forced over SSL/TLS
- Backup transfer managed internally by AWS over an encrypted private network
Monitoring
The infrastructure is equipped with the following service monitoring procedures and mechanisms:
- Server log: All accesses and errors are logged on individual server machines (frontend and database) and the load balancer (aggregated across all machines connected
forto the service). - Email pre-alerts when peak thresholds are exceeded (CPU usage, number of DB connections).
- Uptime Robot: Domain monitoring. If the site is unresponsive, the team is notified via email and internal communication channels (Slack).
- Automatic application error notification: Any errors generated by application functionality on the server are notified to the support team.
- Monitoring and multi-channel alert system: The difference between available and utilized resources (CPU and RAM) is continuously monitored. When preset thresholds are exceeded, the system
invokestriggers autoscaling and communicates the event via variouscommunicationchannels tothetechnical staff.
Disaster Recovery
RPO (Recovery Point Objective): 5 minutes
RTO (Recovery Time Objective): 72 hours