Trust Center - ChargeLab Inc.
Our Commitment to Security
ChargeLab’s mission is to build EV charging solutions that scale, making EV charger deployment fast, affordable, reliable, and most importantly, secure.
Controls
Updated 9 minutes ago
Infrastructure security
| Control | Status |
|---|---|
| Unique account authentication enforced The company requires authentication to systems and applications to use unique username and password or authorized Secure Socket Shell (SSH) keys. |
|
| Remote access encrypted enforced The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection. |
|
| User sessions are automatically terminated after inactivity Terminate (automatically) a user session after a defined condition. |
|
| Unique network system or device authentication enforced The company requires authentication to the "production network" to use unique ids and passwords or authorized Secure Socket Shell (SSH) keys or API keys. |
|
| Continuity and Disaster Recovery plans established The company has Business Continuity and Disaster Recovery Plans in place that outline communication plans in order to maintain information security continuity in the event of the unavailability of key personnel. |
|
| Web Application Firewall Utilized - WAF The Internet-facing application utilizes a Web Application Firewall (WAF) with a minimum of Rate-limiting, Geo-Location, and filtering IP. And if the WAF supports enabling DDOS mitigation and Botnet protection, it should be enabled. |
|
| System activity logged The company captures system activity, including user activity, in transaction logs. |
|
| Data transmission encrypted The company uses secure data transmission protocols to encrypt confidential and sensitive data when transmitted over public networks. |
|
| Production network access restricted The company restricts privileged access to the production network to authorized users with a business need. |
|
| Production data segmented The company prohibits confidential or sensitive customer data, by policy, from being used or stored in non-production systems/environments. |
Organizational security
| Control | Status |
|---|---|
| Confidentiality Agreement acknowledged by employees The company requires employees to sign a confidentiality agreement during onboarding. |
|
| Cybersecurity insurance maintained The company maintains cybersecurity insurance to mitigate the financial impact of business disruptions. |
|
| Access reviews conducted The company conducts access reviews at least quarterly for the in-scope system components to help ensure that access is restricted appropriately. Required changes are tracked to completion. |
|
| Password policies enforced The company has established password policies with minimum system password requirements. The system validates that requirements are met or provides an error message. |
|
| Vendor management program established The company has a vendor management program in place. Components of this program include: - critical third-party vendor inventory; - vendor's security and privacy requirements; and - review of critical third-party vendors at least annually. |
Product security
| Control | Status |
|---|---|
| Data encryption utilized The company's datastores housing sensitive customer data are encrypted at rest. |
|
| Penetration testing performed The company's penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs. |
|
| Vulnerability and system monitoring procedures established The company's formal policies outline the requirements for the following functions related to IT / Engineering: - vulnerability management; - system monitoring. |
|
| Production data backups conducted The company performs periodic backups for production data. Data is backed up to a different location than the production system. |
|
| Production application access restricted System access restricted to authorized access only |
|
| Production database access restricted The company restricts privileged access to databases to authorized users with a business need. |
|
| Network and system hardening standards maintained The company's network and system hardening standards are documented, based on industry best practices, and reviewed at least annually. |
Data and privacy
| Control | Status |
|---|---|
| Customer data deleted upon leaving The company purges or removes customer data containing confidential information from the application environment, in accordance with best practices, when customers leave the service. |
|
| Third party privacy documentation reviewed The company has established, maintains, and reviews, at least annually, documentation on the nature, extent, and purpose of personal information collected, processed, stored, and/or disclosed to third parties. |
|
| Privacy policy reviewed The company reviews the privacy policy as needed or when changes occur and updates it accordingly to ensure it is consistent with the applicable laws, regulations, and appropriate standards. |
|
| Privacy policy available The company has a privacy policy available to customers, employees, and/or relevant third parties who need them before and/or at the time information is collected from the individual. |
Vanta connects to a company's core systems to continuously monitor these controls.