OfficeRnD offers Management Solutions for Coworking spaces, Serviced Offices, and Business Centers. Businesses can manage all aspects of their members and resources, automate billing, invoicing, and payment collection, and provide their community with a white-label member portal and mobile app. Members can leverage OfficeRnD's highly secure, scalable system to provide a great experience to their members.
We take security very seriously and continuously look for opportunities to improve.
To obtain a copy of our attestation and compliance documentation, which provides detailed information on how we maintain system security and incorporate security into our products, please visit our Trust Center. For a high-level overview of our security measures, please read on.
Physical and network security
We use Amazon's AWS platform and infrastructure for OfficeRnD. OfficeRnD employees do not have any physical access to our production environment.
Here are more details about the security setup of AWS.
"Amazon has many years of experience designing, constructing, and operating large-scale data centers. This experience has been applied to the AWS platform and infrastructure. AWS data centers are housed in nondescript facilities with military-grade perimeter control berms. Physical access is strictly controlled at the perimeter and building ingress points by professional security staff utilizing video surveillance, state-of-the-art intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication no fewer than three times to access the data center floors. All visitors and contractors are required to present identification and sign in upon arrival. They are also continually escorted by authorized staff."
In addition to physical security, being on the AWS platform also provides us significant protection against traditional network security issues on the infrastructure, such as:
Distributed Denial Of Service (DDoS) Attacks
Man-in-the-Middle (MITM) Attacks
IP Spoofing
Port Scanning
Packet sniffing by other tenants
Administrative operations
We use two-factor authentication to access all our administrative operations, including infrastructure and OfficeRnD service. Administrative privileges are typically restricted to a small number of employees. Additionally, both application-level and AWS roles are used to ensure that only required operations are allowed for specific users.
Host security
Hosts are segmented, and access is restricted based on functionality. For example, application requests are allowed only from AWS ELB, and database servers can be accessed only from application servers.
Application security
Secure Access β OfficeRnD application servers can be accessed only via HTTPS. We use industry-standard encryption for data traversing to and from the application servers.
XSS β All user inputs are properly encoded when displayed to ensure XSS vulnerabilities are avoided.
Encrypted Data Storage β We do not store sensitive card details on any OfficeRnD network. The keys for various third-party services (like payment gateways) are stored in our database in encrypted form.
Vulnerability scanning and patching
We conduct regular vulnerability scans and annual penetration tests to ensure our systems are secure. Fixes are applied when vulnerabilities are discovered, in accordance with our Vulnerability Management policy.
Data storage and redundancy
We use MongoDB Atlas as our database provider. The automated backup feature is configured. We back up data for up to 150 days. Our database operates on its own, physically distinct, and independent infrastructure, and is engineered to be highly reliable.
Monitoring
We use both internal and multiple external monitoring services to monitor OfficeRnD. If there are any errors or abnormalities in the request pattern, our monitoring system will alert the Operations & Security Team through emails, chat, and phone messages.
β
Disclosure
We are continually working to enhance the security of our system. If you find any security issues, please submit them to [email protected]. Security is our highest priority, and we will ensure that the issue is fixed and updated as soon as possible.