Security

Income Lab is SOC 2 compliant. SOC 2 is an auditing procedure that ensures service providers securely manage data to protect the interests of the organization and the privacy of its clients. Income Lab users or those conducting due diligence may request a copy of our SOC 2 (Type II) report by contacting their account manager or [email protected].

Application Security

Security is our priority

We regularly examine information security best practices and review our security policies and infrastructure to ensure we manage and minimize security risks.

Data Center Security

Income Lab utilizes Amazon Web Service (AWS) cloud technology. This means that physical infrastructure is hosted and managed within Amazon's secure data centers. Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Amazon's data center operations have been accredited under:

  • ISO 27001, ISO 27017, ISO 27018
  • SOC 1/SSAE 16/ISAE 3402, SOC 2, SOC 3
  • PCI DSS Level 1
  • FISMA Moderate
  • Sarbanes-Oxley (SOX)
  • SEC Rule 17a-4(f)

AWS data centers are housed in nondescript facilities and critical facilities have extensive setback and military grade perimeter control berms as well as other natural boundary protection. AWS facilities enjoy top-tier fire detection and suppression systems, redundant power systems, and climate control.

Physical access is strictly controlled both at the perimeter and at building ingress points by professional security staff utilizing video surveillance, state-of-the-art intrusion detection systems, and other electronic means. Amazon only provides data center access and information to employees who have a legitimate business need for such privileges. Authorized staff must pass two-factor authentication (2FA) no fewer than three times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorized staff. All physical and electronic access to data centers by Amazon employees is logged and audited routinely.

PCI

We use PCI-compliant payment processor Stripe for encrypting and processing credit card payments. Income Lab's infrastructure provider is PCI Level 1 compliant. Income Lab does not store or keep any credit card information on its servers.

Data Security

Vulnerability Management

Income Lab takes security very seriously and investigates all reported vulnerabilities. If you would like to report a vulnerability or have a security concern regarding Income Lab services, please email [email protected].

Please provide full details of the suspected vulnerability so the Income Lab security team may validate and reproduce the issue.

Schedule a Demo