AppCheck Compliance, Governance & Due Diligence
AppCheck is committed to protecting the data of its customers, employees and other parties who entrust their personal or confidential data to us for processing. With worldwide levels of data breaches increasing, the growth of Artificial Intelligence being used to find zero-day vulnerabilities, and an ever-changing compliance landscape, it is vital for AppCheck to regularly review and scrutinize data protection practices.
AppCheck performs due diligence and pursues conformance with relevant data protection legislation via a number of means and under a number of enforced or voluntary regulatory and legislative umbrellas and accreditation schemes, as detailed below:
AppCheck Privacy Policy & Data Subject Rights
This document informs you of our policies regarding the collection, use and disclosure of Personal Information we receive from users of AppCheck’s Website (Site).
Read the full Privacy Policy here
AppCheck Cookie Policy
This document informs you of our policies regarding the collection, use and disclosure of cookies we receive from users of the Site.
Read the full Cookie Policy here
General Data Protection Regulation (GDPR)
The General Data Protection Regulation (EU) 2016/679 (commonly known as “GDPR”) is a comprehensive European privacy law that came into effect on May 25, 2018. AppCheck welcomes this law as an important step forward in standardising data protection requirements across the European Union and as an opportunity to benchmark our existing commitments to data protection.
AppCheck is committed to providing robust and best-practice data protection measures in line with the GDPR. AppCheck has taken the opportunity offered by the introduction of the GDPR to ensure that existing policies, procedures and practices are aligned with the GDPR requirements as well as general best-practice.
In addition to the GDPR, AppCheck also aligns with the requirements of the United Kingdom (UK) GDPR (an equivalent regulation to the EU GDPR which took effect on 1 January 2021 specific to the UK) and the UK Data Protection Act (DPA) 2018 (which supplements the UK GDPR).
UK-Based Hosting, Data Storage & Processing
AppCheck’s Enterprise Vulnerability Scanning SaaS Platform makes use of exclusively UK-based onshore data storage and processing facilities for all customer data. Cloud services used by the SaaS Platform exclusively uses UK-based availability zones, regions and environments for all cloud-based storage and processing.
Furthermore, AppCheck currently has no contracted transfer or sub-processing agreements in place to transfer data to any company outside of the United Kingdom.
Sub-processors
AppCheck’s Enterprise Vulnerability Scanning SaaS Platform uses the following sub-processors:
Sub-processor | Purpose | Data Storage Location |
AWS | Provides cloud services to support the SaaS Platform hosting under both the Platform as a Service (PaaS) and the Infrastructure as a Service (IaaS) shared responsibility model. | UK Region |
Provides cloud services to support the SaaS Platform hosting under the Infrastructure as a Service (IaaS) shared responsibility model. | UK Region | |
Node 4 provides two physical UK data centres for co-location services. The AppCheck scanning nodes operate from these data centres. | UK | |
| Used by AppCheck to gain better insights into the use of the AppCheck SaaS Platform helping customers achieve their goals and to get more value from the product. | UK |
AppCheck will maintain the list of sub-processors within the table above, so customers are encouraged to monitor this compliance page.
Electronic Marketing & Cookies (PECR)
The Privacy and Electronic Communications (EC Directive) Regulations 2003 is a law in the United Kingdom which made it unlawful to, amongst other things, transmit an automated recorded message for direct marketing purposes via a telephone, without prior consent of the subscriber. The law implements an EU directive, the Privacy and Electronic Communications Directive 2002.
Although some portions of PECR are superseded by newer GDPR legislation, PECR remains important in establishing commitments regarding HTTP Cookie usage and Electronic Marketing in particular.
AppCheck maintains policies relating to HTTP Cookies and Electronic Marketing and ensures that its practices in this area are open, transparent, and in line with PECR legislative and regulatory requirements.
To request the full policy please email us at: compliance@appcheck-ng.com
ISO/IEC 27001: 2022 Certification (Information Security Management Systems)
Certified through independent third-party assessment, ISO 27001 is an international standard for ‘Information security, cybersecurity and privacy protection’ where mitigation of risk is achieved through the effective implementation of information security controls. Controls applied can include policies, rules, processes, procedures, organisational structure, software and hardware functions. Through consideration of human, technical and physical risks, the aim of an information security management system is the preservation of the confidentiality, integrity and availability of information.
AppCheck holds ISO27001:2022 certification which is continually assessed through a schedule of internal audits and annually audits via external auditors. You can view our ISO 27001 certificate here.
AppCheck additionally ensures that all sub-processors used to support the SaaS Platform are fully compliant with an external industry recognised security framework such as but not limited to; ISO 27001, SOC 2 (System and Organization Controls), PCI DSS (Payment Card Industry Data Security Standard).
Supplier Assurance & Due Diligence
AppCheck recognises that in contractual relationships, it is necessary for customers to seek assurance from vendors such as AppCheck as to their security posture, governance structure, control landscape, accreditation status and compliance position, for customers to proactively manage third party and supply chain risk.
To offer assurance in this area AppCheck maintains ISO 27001 demonstrating its commitment to information security. Where additional information is required, please contact your account manager or, for prospective clients, please see our Contact Us page.
External Assessments & Audits
AppCheck contracts penetration tests and security assessments of its public-facing and internal infrastructure and application services by CREST Accredited Penetration Testing companies. Vulnerabilities discovered during testing are reported to AppCheck and then tracked and resolved in accordance with AppCheck Vulnerability Management policy and industry best practice.
Additionally, AppCheck contracts QMS International Ltd to provide impartial and professional external audits of its ISMS governance and security programmes.
Disaster Recovery & Business Continuity
AppCheck maintains a Disaster Recovery (DR) plan that supports a robust business continuity strategy for key production services, systems and platforms. This plan has been developed from industry accepted methodologies including ISO 27000 standards and encompasses principles of highly available engineering. The DR plan is regularly measured against strict regulatory and governance requirements.
ISO/IEC 9000:2015 (Quality Management Systems)
The International Organization for Standardization 9001 Standard (ISO 9001) is an international standard based on several quality management principles aimed at ensuring that businesses are duly diligent in ensuring the quality of their conducted processes, and in the quality of their offered products and services. It includes best practice recommendations aimed at ensuring a strong customer focus, the motivation and involvement of top management, utilising a process-led approach and committing to continual service and process improvement.
AppCheck has not yet been formally accredited against the ISO 9001:2015 accreditation but maintains an internal Quality Management policy that is based upon and aligned with the ISO 9001 framework, to ensure a continual and ongoing focus on quality throughout the business. AppCheck may choose to pursue formal accreditation against the standard in the future.
Information Commissioner’s Office (ICO) & Data Protection Officer (DPO)
AppCheck is registered with the ICO Data Protection Register, reference number ZA442854 (click here to view our ICO registration certificate). AppCheck has also appointed Wayne Murphy as its Data Protection Officer (DPO) who is registered with the ICO and can be contacted with any data protection queries at wayne.murphy@appcheck-ng.com.
ISMS & Corporate Governance
AppCheck has in place a robust ISMS governance structure, including an ISMS review committee that performs regular ISMS review meetings to ensure continual improvement in the operation of our established ISMS.
The AppCheck ISMS review committee meets regular to review and update organisational security practices, policies and controls and to review the threat landscape. The committee tracks risks to AppCheck in a Risk Register and performs Risk Assessment at the inception of new projects as needed.
Reports and minutes of ISMS review meetings are maintained.
Further Information
If you have any queries or wish to speak to us about how your information will be used, then please contact us at AppCheck Ltd, Unit 1, Centre 27 Business Park, Bankwood Way, Birstall, WF17 9TB and / or compliance@appcheck-ng.com and / or 0113 887 8380.
Any changes we may make to our policies in the future will be posted on the relevant page and, where appropriate, notified to you by email. Please check back regularly for updates.