Data is encrypted in transit – all account information is encrypted in transit and stored in a secure data center hosted by Google Cloud Platform (GCP).
- Encrypted connection protocols included HTTPS, SSL and TLS.
- Communication between ActivTrak cloud and the agent uses HTTPS/TLS with AES-128 encryption.
- Mutual authentication is provided by a combination of digital certificate and per-instance shared key, which is created during deployment.
Data is encrypted at rest – we use several layers of encryption to protect customer data at rest in Google Cloud Platform (GCP).
- Data stored within the cloud is stored using AES-256 encryption.
- Data is automatically encrypted prior to being written to disk.
- All data, including screenshots, videos, and activity logs, are split into discrete blocks which are encrypted.
ActivTrak complies with your organization’s authentication security standards and protocols.
- We support single sign-on (SSO) and Multi-factor authentication (MFA).
- When SSO and/or MFA is enabled, we delegate the user authentication process to identity providers that support the Security Assertion Markup Language (SAML) 2.0 standard.
- We have certified SSO for the following identity providers: Okta, Azure AD, OneLogin, and Google Suite.
Rigorous security testing
We regularly test our infrastructure and applications to isolate and remediate vulnerabilities. We also work with industry security teams and third-party specialists to keep our users and their data safe. ActivTrak is designed with multiple layers of protection across a distributed, reliable infrastructure. All ActivTrak data is stored in a secure data warehouse managed and secured by Google Cloud Platform (GCP).
You own the data in your account. ActivTrak does not view the private information collected by your account. Our policy is to take a ‘least-privilege’ approach, meaning we only access customer data upon request for support from an authorized administrator for your account.
- Customer information stored in the cloud is encrypted at rest with our organizational keys.
- ActivTrak employees do not have access to this information unless temporarily granted by the customer for troubleshooting.
- User access is highly restricted and must be approved by an organizational admin you designate.
ActivTrak is designed with multiple layers of protection across a distributed, reliable infrastructure. All ActivTrak data is stored in a secure data warehouse managed and secured by Google Cloud Platform (GCP).
- Servers are hosted in a SOC2 type 2 compliant datacenter, across multiple availability zones/regions.
- Google’s physical infrastructure has been accredited under ISO 27001, SOC 1/SOC 2/SSAE 16/ISAE 3402, PCI Level 1, FISMA Moderate and Sarbanes-Oxley.
Our technology empowers organizations to identify behavioral trends and gain insight into human work behavior on digital devices in the workplace. We take employee privacy seriously and do not promote the use of ActivTrak as a form of big brother, but instead recommend being transparent with employees about the use of ActivTrak. The intent of ActivTrak is to better understand how to increase organizational productivity, strengthen cyber defenses and lift employee engagement.
Over 130,000 organizations trust us with their most important work
Below are ways we help protect your privacy, while still retrieving the data necessary to manage your account and analyze productivity
Scheduling Working Hours
Accounts are provided with a scheduling feature that allows an administrator to set up a schedule where the ActivTrak only collects activity during the user's set work times.
Do Not Track List
Once a user is placed on the Do Not Track list ActivTrak will completely stop collecting any of the user's data and will only begin collecting data once they are removed from the list.
When an account is set up, screenshots are disabled by default. We recommend enabling screenshots only in response to specific activities, or that you leave them off completely.
After an account is created, admins are the only people who can sign in and view user data by default. This can be changed to allow users access based on different viewer roles.
To protect employee passwords and keystrokes, ActivTrak does not provide any type of keylogging feature.
No Video Monitoring
We do not provide a video monitoring feature and the ActivTrak agent does not have access to the users' camera. Employees can work privately wherever they are as well as keeping sensitive information that may be shown on their screen from being recorded.
Data Recovery and Retention
As long as your account is active, you have full control over specific user information retained, including: screenshots, videos and length of time. Activity Log Data, videos and screenshots can be exported via a variety of methods in compliance with Right to Data Portability (GDPR, Article 20).
ActivTrak never stores credit card details associated with your account. All credit card information is collected and processed by a third-party, PCI compliant payment processor. Your card information is passed directly to them, meaning your credit card information never touches our servers.
We do not have access to any password details. All passwords are encrypted in transit, and stored in a secure data center.
ActivTrak supports compliance initiatives such as HIPAA, COPPA and GDPR. Ultimately customers are responsible for evaluating their own compliance with the law.