Data Protection

At Measured, we implement enterprise-grade security measures and conduct regular audits of our applications, systems, and networks to ensure the integrity and reliability of the infrastructure that powers the solutions our customers depend on.

What we stand for

At Measured, we have open communication about how we protect your data and operate our platform. Our goal is to give you full confidence in our security practices, privacy policies, and compliance posture. We recognize that each business has unique needs. If you have questions that aren’t addressed here please contact  security@measured.com

Organizational security

Employee access

Access for our employees is governed by the privilege of least privilege required. Prior to joining, all new employees must undergo a standard background check. Upon joining, all access requests are logged and approved by authorized personnel. Multi-Factor Authentication (MFA) is enforced on critical services. Measured also has a quarterly access verification process in place where we check for privileges and continued business needs.

Identity & access management

The Measured Platform’s Client Portals’ identity and access management is powered by Okta, a global leader in secure authentication. Access to our platform is governed by Role-Based Access Control (RBAC), ensuring users can only access data relevant to their roles. All user logins are protected by mandatory Multi-Factor Authentication (MFA).

Passwords

Internal password policies are aligned with industry best practices that enforce length, complexity, and restrictions. Secure password vaults are provided to all employees.

Mobile device management (MDM)

MDM software is used to enforce controls that ensure our workforce devices stay safe and secure. Examples of enforced settings include full disk encryption for all devices, use of endpoint protection, along with automated system updates and patches.

Security incident detection and response

Incident response is based on the NIST framework. The Information Security Team employs a suite of tools and technologies that are used to detect and alert on suspicious activities. Alerts are routed to the Security Team and follow Incident Response Plan procedures.

Security awareness training

Security awareness training is delivered to all employees at onboarding and annually thereafter. In addition to awareness training, development employees also take secure coding training at onboarding and annually thereafter. Regular phishing exercises are also conducted to assess the effectiveness of the training.

Business continuity and disaster recovery

Business Continuity and Disaster Recovery Plans are maintained and regularly tested.

Vulnerability management

Vulnerabilities are managed through a Vulnerability Management Program aligned to industry best practices. Threats are triaged, classified, and remediated upon prescriptive timelines. A formal bug bounty program with financial rewards is not offered at this time.

Risk management

Risk is continuously managed through a Risk Management Program aligned to industry best practices. Risks are identified, analyzed, evaluated, treated, and monitored according to policy. Formal assessments are conducted annually and all risks and exceptions are captured and logged.

Vendor reviews

Vendors are managed through a Vendor Management Program aligned to industry best practices. Each vendor is evaluated and classified based on assigned risk. Critical vendors are assessed at least annually and subjected to enhanced security evaluations to ensure compliance with security practices.

Information security policies

Measured maintains a library of policies and procedures that align with ISO27001 standards.

Encryption

Measured encrypts all data in-transit using TLS 1.2 or greater and at rest using MD5 or SHA 256. Cipher suites follow industry standards for security and performance.

Security testing

All of our code repositories undergo regular Software Composition Analysis (SCA), Static Application Security Testing (SAST), and third-party penetration testing is conducted annually.

Secure software development lifecycle plan

Measured follows a Secure Software Development Lifecycle to ensure security is embedded at every stage of our product development process. From design to deployment, we conduct regular code reviews, threat modeling, static code analysis, and dependency scanning. This proactive approach helps us deliver reliable, secure software while minimizing risk.

Resilience

At Measured, resilience is core to our platform design and operations. We leverage a cloud-only distributed architecture to ensure high availability, fault tolerance, and rapid recovery. Automated monitoring and redundancy across critical systems helps us maintain business continuity.

Third-party attestation

Measured works with an independent third-party auditor to maintain an annual SOC 2 Type II report, providing objective validation of our operational controls across security, availability, confidentiality, and integrity. This ongoing certification ensures that our systems and practices meet the highest standards of trust and transparency. In addition, Measured is ISO/IEC 27001:2022 certified.