We take security seriously.
We want you to feel confident that Tribal Habits is a safe and trustworthy portal for your staff, clients and prospects to build a community of knowledge.
Tribal Habits is ISO 27001 certified, and maintains an active Information Security Management System that is regularly reviewed and audited to ensure ongoing compliance and effectiveness.
Copies of our Security Practices or any of our internal security policies can be found on our security portal
Security at Tribal Habits is underpinned by the following eight core principles:
We host all data with Amazon Web Services in Sydney, Australia. AWS is the gold standard for SaaS platforms offering unparalleled built-in military-grade security options. This includes DDOS protection, customised firewalls, AI-driven intrusion protection, automated vulnerability scanning and more.
All data stored (at rest) at Tribal Habits is encrypted by default using an industry-standard AES-256 encryption algorithm. This includes our database as well as all files, assets and code. All data transferred to users is encrypted via TLS security using a SHA2 certificate with a full 2048 bit key.
Our code is high quality from conception to deployment. We use automated static code analysis alongside human review to ensure best practices are implemented across code pushes. Responsive development means new features, resiliency improvements and bug fixes arrive weekly and seamlessly.
We monitor our security posture 24/7 via AWS Security Hub. This includes AWS Guardduty for real-time intrusion alerts and AWS Inspector for automated vulnerability reporting. We also engage independent 3rd party annual vulnerability and penetration testing.
A critical part of security are our people. All Tribal Habits staff complete regular (semi-annual) training on information security, social media and phishing. Development teams undertake extra training on OWASP Top 10 and best practices in secure development principles.
Tribal Habits utilises AWS Elastic Beanstalk technology to distribute our platform across multiple instances and availability zones within the AWS infrastructure. Load balancers and auto-scaling rules ensure we have multiple failover instances to prevent outages. Our uptime is live and public.
While the vast majority of Tribal Habits code is developed internally, we integrate with selected trusted partners to provide world-class features when required. All our partners must have ISO 27001 or SOC 2 Type 2 certifications. Partners are integrated via secure Restful APIs with restricted access to key features.
Our security practices are constantly under review, including analysis and reports from external third parties. We have detailed Incident Management and Disaster Recovery plans, including simulated incidents and game day security training for our team. We regularly review and update our code with latest practices.
Tribal Habits availability is consistently above 99.99%. Customer data is backed up daily allowing a point in time restore for our back-end databases in the event of disaster recovery. If we ever have a customer-impacting situation, we will make you aware of it via emails to portal administrators and keep you continually updated. Our status page (status.tribalhabits.com) is also continuously updated with incident responses, as well as planned outages.
Yes. The application and infrastructure behaviour of Tribal Habits is monitored using multiple solutions including Amazon Web Services (AWS) Control Tower, Guardduty and CloudWatch alarms, as well as error reporting for both server and client errors. Our status page (status.tribalhabits.com) provides real time reporting on key infrastructure.
Yes. Every part of the Tribal Habits platform is distributed across multiple instances and availability zones within the Amazon Web Services (AWS) infrastructure. Databases, application servers, web servers, jobs servers, and load balancers as well as backend support services all have multiple failover instances to prevent outage from single points of failure.
Yes. All communication to and from Tribal Habits servers use HTTPS (TLS only – SSL is no longer supported) to both encrypt all communications to maintain privacy and provide a guarantee of Tribal Habits server authenticity. Our HTTPS certificate is a SHA2 certificate using a full 2048 bit key, and issued by AWS and renewed every 12 months.
Yes. Tribal Habits utilises a combination of tools to protect the Tribal Habits infrastructure.
We utilise a variety of real-time monitoring to alert to any unexpected data usage and have the ability to add server instances in response to unexpected high server usage.
Yes. Tribal Habits code is high quality from conception to deploy. We use automated static code analysis alongside human review to ensure development best practices are implemented across code pushes. Responsive software development means new features, resiliency improvements, and bug fixes arrive weekly (often daily), and seamlessly.
Within the Tribal Habits platform, customer data is stored in a secure, encrypted Amazon RDS. This customer database is backed up daily and stored for 35 days. These back-ups can be used for disaster recovery purposes by Tribal Habits (whole system restore). Where a client requests a backup of their own data from a point in time (e.g. they deleted something and now they want it back), we cannot guarantee this will be possible at all times if our platform/database has upgraded/changed structure.
Tribal Habits organisations are ‘walled’ from each other (separate schemas within our database). Each organisation has their own subdomain for accessing Tribal Habits. Users can login can only via their own subdomain and are blocked from accessing any other subdomains (user accounts are linked to a single schema). All content created by users in an organisation is only visible to other users of the same organisation. All URLs are authenticated against the user’s organisation, preventing anyone from sharing URLs to people outside their organisation. As noted above, video assets cannot be downloaded and are restricted to playback by authenticated users within their Tribal Habits portal. Images and files displayed or made available in your Tribal Habits modules using four-hour time expiring URLs.
Yes. We only use dummy data for our testing and preview environments.
The Tribal Habits platform is run on fault-tolerant servers at Amazon Web Services (AWS). Our servers at AWS are backed by UPS electricity supply, 24 hour monitoring of electrical, mechanical and life support systems, automatic fire detection and suppression equipment, climate controlled environments, and NIST 800-88 destruction techniques for decommissioned storage devices. Our servers at AWS are hosted in multiple availability zones in each location, with each availability zone physically separated from each other to minimise risks of concurrent physical impacts on servers.
All customer data, with certain secure integrations as outlined below, is stored on AWS servers and databases located in Sydney, Australia. Our databases are encrypted at rest with an AWS customer master key and industry standard AES-256 encryption.
We integrate with a limited number of major external providers for critical systems. We review and select trusted, global and large providers for our critical integration and use only secure RESTful APIs to transfer only necessary data. Access to data stored by our trusted external partners is limited to employees authorised for that specific purpose. Some limited customer data is stored securely in the US with our integration partners. Please contact us for more information about secure storage.
Tribal Habits as a company also stores some customer data for marketing, management, finance and administrative purposes internally. To clarify, this is limited to information such as customer logos, invoices and customer marketing communications. Such administrative data is stored in a major cloud storage environment with access strictly limited to Tribal Habits staff (no contractors or third parties) on a user-by-user basis, with version history, back-ups and access monitoring.
Yes. Between our streamlined, rapid approach to application delivery and our highly automated server infrastructure, Tribal Habits’ quickly addresses security issues as they arise. These technology and process structures allow Tribal Habits to rapidly adapt as new threats are identified.
Yes. Tribal Habits’ patch management process pushes security updates fast and consistently.
Tribal Habits’ Cybersecurity Incident Response Plan is responsive and repeatable. We use standard incident response process structures to ensure that the right steps are taken at the right time.
Yes.
First, we conduct annual external 3rd party vulnerability and penetration testing. This includes automated testing against the OWASP framework as well as open ‘white hat’ hacking attempts as both external, non-privileged and privileged users.
Second, we conduct annual external 3rd party reviews against the AWS Well Architected framework for additional testing of our core infrastructure.
Finally, we also have internal and external audit processes to ensure that processes are implemented and working as intended.
Yes. Code for Tribal Habits is specifically developed and tested following principles set out in the Open Web Application Security Project (OWASP) Top Ten framework. Specific reporting against all elements of the framework is included in 3rd party security reviews.
Within our Amazon Web Services (AWS) environment, we utilise a strict Identity Account Management framework. Access to the Root Account at AWS is held only by the Tribal Habits CEO with a two-factor login process. Other employee access to AWS is limited to the CTO and is also conducted via two-factor authentication. Security Policies are applied to all AWS identities, limiting access to servers, databases and file storage based on their role and/or purpose. AWS Guard Duty is activated to alert any unusual IAM (or API) activity. We have separate AWS accounts for production and staging environments, as well as for finance and disaster recovery, to provide additional layers of protection between our core infrastructure.
Outside of AWS, we utilise a centralised password management system for all Tribal Habits staff and our applications and integrations. Internally, we require minimum 20 character randomly generated passwords. The password management system conducts regular audits of staff logins to ensure strong passwords and allows for bulk-password changes in the event of any security concern.
The passwords for customers and their users are stored in an encrypted environment (salted and hashed). Passwords must meet minimum requirements (8 characters, upper and lower characters, including a number or non-standard character). Passwords can be set or reset by customer administrators, but cannot be viewed. Users can also request password resets of their own password through an automated email service. Tribal Habits user accounts are automatically locked after 10 failed password attempts and can only be unlocked by their portal administrator. Neither Tribal Habits staff nor portal admins can see or access user passwords.
All users within Tribal Habits have a unique log-in ID. This log-in ID is tracked each time it us used to access a portal. Each log-in ID can only access the unique Tribal Habits portal is it assigned to. Each log-in ID is linked to a twelve hour time-expiring session cookie.
Some users within each Tribal Habits portal can be granted Administrative privileges for their portal. Administrative privileges can only be granted by an existing Administrator within your platform. To provide support, servicing and testing, some Tribal Habits staff have Super Administrator privileges which grant access to all Tribal Habits portals. Super Administrators can only be created manually by the Tribal Habits CEO and CTO, and are restricted to vetted internal Tribal Habits staff only.
Yes. Tribal Habits supports the SAML 2.0 single sign on (SSO) protocols for customers wishing to further improve user security. Please contact Tribal Habits Support to activate SAML on your portal.
All employees must successfully complete a security background check before working at Tribal Habits. Tribal Habits regularly communicates with staff about its obligation to safeguard confidential information. We provide online training on confidentiality, privacy, and information security for all new employees. In addition, all staff are required to complete an annual privacy and security training and are tested on the materials presented. Every employee must follow our code of conduct, sign a confidentiality and non-disclosure agreement as a condition of employment, and follow our information security policies. We conduct random audits of each employee’s IT and physical security measures.
| Cookie | Duration | Description |
|---|---|---|
| __cf_bm | 1 hour | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
| __hssc | 1 hour | HubSpot sets this cookie to keep track of sessions and to determine if HubSpot should increment the session number and timestamps in the __hstc cookie. |
| __hssrc | session | This cookie is set by Hubspot whenever it changes the session cookie. The __hssrc cookie set to 1 indicates that the user has restarted the browser, and if the cookie does not exist, it is assumed to be a new session. |
| __stripe_mid | 1 year | Stripe sets this cookie to process payments. |
| __stripe_sid | 1 hour | Stripe sets this cookie to process payments. |
| cookielawinfo-checkbox-advertisement | 1 year | Set by the GDPR Cookie Consent plugin, this cookie records the user consent for the cookies in the "Advertisement" category. |
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| CookieLawInfoConsent | 1 year | CookieYes sets this cookie to record the default button state of the corresponding category and the status of CCPA. It works only in coordination with the primary cookie. |
| elementor | never | The website's WordPress theme uses this cookie. It allows the website owner to implement or change the website's content in real-time. |
| JSESSIONID | session | New Relic uses this cookie to store a session identifier so that New Relic can monitor session counts for an application. |
| rc::a | never | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| rc::c | session | This cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks. |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
| Cookie | Duration | Description |
|---|---|---|
| __hstc | 6 months | Hubspot set this main cookie for tracking visitors. It contains the domain, initial timestamp (first visit), last timestamp (last visit), current timestamp (this visit), and session number (increments for each subsequent session). |
| _ga | 1 year 1 month 4 days | Google Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. |
| _ga_* | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
| hubspotutk | 6 months | HubSpot sets this cookie to keep track of the visitors to the website. This cookie is passed to HubSpot on form submission and used when deduplicating contacts. |
| sbjs_current | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_current_add | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_first | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_first_add | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_migrations | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_session | 1 hour | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| sbjs_udata | session | Sourcebuster sets this cookie to identify the source of a visit and stores user action information in cookies. This analytical and behavioural cookie is used to enhance the visitor experience on the website. |
| Cookie | Duration | Description |
|---|---|---|
| _cfuvid | session | Description is currently not available. |
| blgj5lst | 5 days | Description is currently not available. |
| m | 2 years | No description available. |
| oxetqk28 | 5 days | Description is currently not available. |
| x4mk8hq1 | 5 days | Description is currently not available. |