Security statement

This security statement applies to the products, services, websites and apps offered by iBabs BV, located at Maelsonstraat 28-4 in Hoorn, the Netherlands (hereinafter together with its subsidiaries and affiliates, “iBabs”), except where otherwise indicated. We designate these products, services, websites and apps in this Statement with the word “services.”

ISO CERTIFIED MANAGEMENT SYSTEM

Our management system is set up according to the standards of ISO 9001 and ISO 27001. An important aspect of iBabs’ management system is that continuous improvements in quality and information security are continuously sought and the continuous increase in the level of customer satisfaction. iBabs is ISO 9001:2015 and ISO/IEC 27001:2022 certified and meets the requirements of norm ISO 27002.

SECURITY POLICY

iBabs has drawn up an information security policy that gives direction to the organization with regard to all activities related to information security. This policy is actively promoted to the employees and applied in the business operations. iBabs maintains, monitors and reviews its information security policy at least once a year, in such a way that it complies with business requirements and relevant laws and regulations. Compliance with the policy is tested, among other things, from internal audits.

STAFF

iBabs verifies the background of new employees by conducting screening. Among other things, we ask for a valid certificate of conduct (VOG). All employees of iBabs also sign for confidentiality. All iBabs employees know the information security policy and the general methods that can be used to compromise information security policies and measures (for example through Social Engineering).

ASSET MANAGEMENT

iBabs records how assets are managed, classified, retained, and removed. Equipment used by iBabs employees are equipped with full hard drive encryption and have up-to-date antivirus software. When equipment is issued to employees, it is signed for receipt and the way in which the equipment must be used by the employee, including any additional measures to be observed. Records of removed and destroyed equipment shall be kept.

ACCESS CONTROL

iBabs only provides access if absolutely required and is limited to authorized persons who need access to perform their function. Access is denied to people who have no or no longer authorized access. iBabs also reviews employee permissions quarterly and immediately revokes access rights once an employee’s employment is terminated. Access is protected by a login name and password. Each employee has a personal login name and a password to log in. Passwords have a minimum length, are complex, expire and can be blocked. Passwords cannot be reused. Passwords are never
passed on by phone or email.

ENCRYPTION

iBabs encrypts the data being sent with secure cryptographic SSL/TLS protocols. iBabs is offered in the cloud end-to-end https. This means that the Web Application Firewall (WAF) does check packet content, but then packs https again to forward to the web nodes on the internal network. All data is also protected as long as it is stored on the basis of file encryption with AES-256 encryption with its own encryption key per site. Each iBabs “site” (tenant) has its own site encryption keys for file data. The propensity key prevents sites from accidentally consulting each other’s documents due to a programming error. The iBabs Apps are also https encrypted in combination with certificate pinning and the Encryption of files on local storage.

PHYSICAL SECURITY

iBabs’ information systems and technical infrastructure are hosted in the Microsoft Azure Western Europe (Netherlands) data center with a diversion to Northern Europe (Ireland). More information can be found at: docs.microsoft.com/nl-nl/azure/security/ fundamentals/physical-security

VULNERABILITY MANAGEMENT AND PENETRATION TESTING

iBabs works with a documented vulnerability management program. This program scans, identifies, and fixes vulnerabilities in the security of servers, workstations, network devices, and applications. All networks, including testing and production facilities, are regularly scanned by trusted third-party providers. Servers receive highpriority critical patches. Other patches are applied when needed. iBabs regularly performs internal and external penetration tests and solves problems based on the severity of the results. Euronext InfoSec results in an automated scan several times
a month. Radically performs OpenSecurity and crystalbox pentest (code and backends) at least once a year.

CAPACITY MANAGEMENT

iBabs has no limit in capacity. iBabs has a data distribution layer allowing different iBabs service sets to operate as 1 virtual. Performance and capacity are monitored daily and can be scaled at the touch of a button within Microsoft Azure. This allows us to expand internationally if iBabs network and customers host their data locally.

NETWORK SECURITY

Parts of iBabs are in their own subnets, in their own Vnet and sealed with so-called Network Security Groups (NSG). To access iBabs resources, only secure connections are used with named accounts, 2 factor verification, WAF, Firewall and 24/7 monitoring with Intrusion Detection (IDS) and resource monitoring.

DEVELOPMENT

The iBabs development team uses safe techniques and best practices in the field of programming. OWASP Top Ten is the starting point. Developers participate annually in formal training in secure web application development practices. The development, test and production environments are separate. All changes are reviewed and documented by experts for performance, audits and research purposes, before being deployed in the production environment.

SECURITY INCIDENT MANAGEMENT

iBabs works with security incident policies and procedures. The policies set out the initial responses, the investigation, customer notifications (where minimum applicable laws are complied with), public notices, and remedial action. This policy is regularly evaluated and tested twice a year.

INFRINGEMENT NOTICES

Despite all efforts, no method of transmission over the Internet and any method of electronic storage is completely secure. iBabs cannot guarantee absolute security. iBabs also does not guarantee that the Software will work without errors or that all errors will always be corrected. iBabs will make every effort to correct errors in the software within a reasonable period of time in accordance with terms and conditions. However, if iBabs learns of a security breach, iBabs will notify affected users so that users can take appropriate protective measures. Infringement notice procedures follow the guidelines from applicable contractual obligations and laws and regulations. iBabs makes every effort to keep customers fully informed of issues affecting the security of their account. iBabs is committed to giving customers all the information they need to meet their own legal reporting obligations.

INFORMATION SECURITY AND BUSINESS CONTINUITY MANAGEMENT

Customer data is continuously backed up (files and database) with a retention of 28 days. This is a native Microsoft Azure functionality. The virtual machines for running the code are backed up daily. These do not contain customer data, but are backed up to.b continuity of the system. Here too, a retention of 28 days applies. iBabs will make every effort to achieve uninterrupted availability (7 days a week, 24 hours a day) of the SaaS Service. iBabs will endeavour to inform the customer about the nature and expected duration of the interruption in the event of the SaaS Service not being available, due to malfunctions, maintenance or other causes.

24/7 SUPPORT

With 24/7 access and support, we have already helped some 300,000 professionals to have more easier and more effective meetings. Both online and offline.

Service Level Agreement

An overview of all our iBabs SLA Reports can be found on our knowledge base: SLA Reports 2025

USER RESPONSIBILITIES

As a user, you want to keep your data safe, to maintain the security of your account by using complex passwords and keeping them secure. In addition, choose efficient security of your own systems. In addition to the default settings, you have additional options to influence security:

  1. API Secret, can only be used viaMDMversions. This allows the API for a specific site to be accessed only by MDM managed apps of the organization itself.
  2. IP Level restriction. This can only be limited for the web interface or for the web interface and apps (api).
  3. Set password expiration period.
  4. Minimum password length, default 8 but can be extended.
  5. Common security settings:
    a. Allow open from other app
    b. Allow document mailing
    c. Allow camera usage
    d. Allow copying and pasting
    e. Allow password remembering
    f. Avoid snapshot
    g. Clicking links in PDF-allow documents
  6. Link to Microsoft Entra ID (previously AzureAD). If this is used, it is enforceable that only Microsoft Entra ID (previously AzureAD) is used. Sync with an Microsoft Entra ID (previously AzureAD) group is also possible.
  7. Alert emails on changes to calendar type rights
  8. 2 factor authentication. Per user.
  9. Adjustable timeout on oAuth tokens.

LOGS AND MONITORING

In application and infrastructure systems, information is tracked through a centrally managed logbook. Authorized iBabs employees solve problems, check security, and perform analyses. The logs are kept on the basis of legal guidelines. If there are security incidents that affect customer accounts, iBabs provides customers with help and access to our logs to the extent that is reasonable and possible. Log trails on security related customizations in iBabs itself:

  1. Authentication logging
  2. Logging function
  3. Password logging
  4. Activity logging

SESSION DURATION AND AUTOMATIC LOGOUT

Within iBabs, a logged-in session is automatically terminated after thirty minutes of inactivity. If the user does not make use of the remember password functionality, the session is terminated immediately once the browser or app is closed.

BACKUPS AND RECOVERY TESTS

With regard to customer data backups, an annual failover test is performed. In addition, a yearly Disaster Recovery test is carried out to validate the effectiveness of business continuity measures. The retention period for backups is thirty days.

RTO AND RPO OBJECTIVES

The following objectives have been established with respect to the Recovery Time Objective (RTO) and Recovery Point Objective (RPO):

  • RTO: the production environment will be operational again within sixty minutes.
  • RPO: no loss of production data, or at most limited to the moment of the last backup (a maximum of five seconds).