Security
Security is one of the biggest considerations in everything we do. If you have any questions, or encounter any issues, please contact us at security@tenfold.com.
OWASP Certified
Tenfold passed an in-depth security audit, using best practices code scanners (BURP) and code analysis (Checkmarx) in 2014. Each year, this audit is renewed.
SSL and HSTS
Tenfold forces HTTPS for all services, including our dashboard, browser extension, and website. We regularly audit our security implementation, the SSL certificates we use, our Certificate Authorities (CA)’s, and the strength of our ciphers. We use HSTS to ensure browsers interact with Tenfold only over HTTPS.
Encryption
All passwords are encrypted on disk with AES-256. Decryption keys are stored on separate machines.
Disclosure
We investigate all reported security issues. If you discovered a bug in Tenfold’s security, please quickly email us at security@tenfold.com. We will respond immediately to confirm the potential problem. We request that you not publicly disclose the issue until giving us a reasonable time to investigate.
Salesforce Security Audit – Certified AppExchange
Each year Salesforce performs an in-depth security review, which is a requirement to list on AppExchange.
CCPA
For additional information about Tenfold’s CCPA compliance program, please click here for more details.
GDPR
For additional information about Tenfold’s GDPR compliance program, please click here for more details.