ShareVault by ShareVault provides bank-grade security, privacy, availability, and compliance. It is used for applications that demand adherence to stringent security standards for the protection of sensitive information, ensuring compliance with various standards and offering cutting-edge security and privacy functionality. ShareVault is ISO 27001:2013 certified, confirming that it has implemented necessary security measures to safeguard security management systems from compromise or unauthorized access, assuring data integrity, information security, and confidentiality. Compliance has been confirmed by SRI, an independent ISO certification organization. The scalable cloud services, dedicated hardware, secure data center, advanced resiliency functions, and secure networking technology on which ShareVault is deployed are provided by Amazon Web Services (AWS), with DNS Security and DDoS protection assured by Cloudflare. ShareVault servers are located in an AWS virtual private cloud (VPC), using dedicated instances assuring that the hardware is not shared with other AWS accounts. Each of ShareVault's AWS server instances are hardened according to industry best practices and relevant security standards. Crowdstrike provides information security for ShareVault, including 24/7 real-time monitoring for network/applications, system anomalies, emerging threats, event investigation, detection escalation, and incident response. The security architecture uses separate public and private subnets with AWS security groups for isolation and limited access. Backend server maintenance is done via VPN through a firewall. ShareVault infrastructure is based on a high-availability architecture with redundancy at multiple levels. ShareVault has delivered over 99.9% uptime since 2006. There are at least two instances of each server type in different AWS availability zones for geographic redundancy and real-time failover. Daily snapshots of all servers are stored in encrypted AWS S3 for quick disaster recovery if both availability zones are affected. Encryption keys for customer data files are stored in a separate AWS region for disaster recovery. Software updates, enhancements, and bug fixes can be applied in stages to one server at a time, while other server(s) handle user activity. ShareVault accounts can be deployed in any of the 33+ geographic regions in AWS's global infrastructure to comply with data residency regulations. ShareVault practices SSLDC (Secure Software Development Life Cycle) management. ShareVault software engineers and quality control personnel are trained on secure software development methodologies. The application undergoes third-party vulnerability assessments, including automated scanning and manual penetration testing. Files stored on ShareVault are encrypted at rest with AES 256, with key management that prevents access via the back end. Keys are accessible only through an authenticated session and are never stored to disk. The only way to open files in ShareVault is through the ShareVault web application. ShareVault offers Customer Managed Keys (CMK) for Enterprise, providing high-level encryption key management security without the complexity of maintaining your own HSM. It supports 'Bring Your Own Key' (BYOK) for further isolation and increased security. Encryption in Transit with Extended Validation ensures all connections to ShareVault servers are via HTTPS over Secure Sockets Layer (SSL), providing AES 256 encryption in transit. The Enhanced Validation (EV) certificate assures best practices for domain identity validation.