Table of Contents

Sonar and General Data Protection Regulation (GDPR)

Read Time: 2 mins

Security in the Cloud

Sonar leverages the robust technical security and privacy solutions provided by Microsoft Azure to ensure the confidentiality, integrity, availability, and privacy of client data in the cloud.

Our Cloud Service Provider, Microsoft Azure, adheres to stringent security standards and compliance frameworks, including GDPR, SOC 1, and SOC 2. These certifications are validated through rigorous third-party audits to verify adherence to security controls. For a complete list of Microsoft’s certifications, please refer to the Microsoft Service Trust Portal.

Data Security: Industry-Standard Encryption and Secure Connections

Sonar protects data in transit and at rest using advanced encryption protocols. All data transmitted to and from our servers is encrypted using HTTPS (TLS 1.2 and above). For data at rest, we employ AES 256-bit encryption to meet and exceed industry standards.

Network Security: Intrusion Detection and Prevention

Our networks are secured using Microsoft Azure’s advanced firewalls, configured according to industry best practices for ingress and egress security. These systems include Extended Detection and Response (XDR) capabilities, providing protection against threats such as malware, brute-force attacks, SQL injection, Denial of Service (DoS), Distributed Denial of Service (DDoS) attacks, and other vulnerabilities.

Additionally, Azure Network Security Groups (NSGs) control inbound and outbound traffic, employing rule-based filtering based on protocol, source, destination, and port information.

Sonar has implemented detailed operating procedures, security policies, and processes to ensure the safety of employees, partners, and customers, while maintaining the integrity and availability of our information systems.

Data Governance

Sonar recognizes its responsibilities under the Cloud Shared Responsibility Model for services provided through Microsoft Azure. As a company with operations and customers in both the United States and Canada, we prioritize compliance with GDPR and US privacy standards to protect the confidentiality, integrity, and availability of customer data.

Sonar is actively pursuing SOC 2 compliance to align with our commitment to data privacy and security. Our Privacy Policy reflects these commitments and ensures transparency around data handling practices.

European Data Transfer

Sonar adheres to data transfer requirements under GDPR. The European Commission has recognized Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) as providing adequate protection for personal data. This adequacy ensures seamless data flow between the EU and Canada without additional safeguards.

Microsoft further supports data transfer compliance with Standard Contractual Clauses (SCCs) incorporated into its enterprise agreements. These clauses provide a legal framework for transferring data from the European Economic Area, Switzerland, and the UK to third countries in compliance with GDPR Article 46 requirements.

How did we do?

Sonar's Security Strategies

Contact