March 2018 Summaries
2 posts from Nylas
Filter
Month:
Year:
Post Summaries
Back to Blog
Achieving SOC 2 certification in security and confidentiality is a crucial step for Nylas in building customer trust through rigorous engineering and adherence to best practices. SOC 2, which stands for System and Organization Controls, is a highly regarded standard in security and compliance, encompassing a range of organizational processes and practices. Nylas's journey to certification involved collaborating with A-LIGN auditors to assess their current operations, identify gaps, and implement necessary improvements to meet SOC 2 standards. This process included selecting specific trust principles, such as security and confidentiality, and developing a roadmap to ensure compliance, which involved detailed documentation and a formal audit. Even after achieving certification, Nylas commits to ongoing audits and improvements, aiming for further certifications like ISO27001, to enhance their API's reliability and protect sensitive data effectively.
Mar 10, 2018
872 words in the original blog post.
Nylas emphasizes the importance of data security and compliance with the General Data Protection Regulation (GDPR), which impacts both EU and non-EU companies handling EU citizens' personal data. GDPR, effective from May 25, 2018, expands the definition of personal data to include a wide array of information, with stricter protections for sensitive data. As a data processor, Nylas is responsible for adhering to GDPR requirements such as the right to data deletion, data portability, and breach notifications within 72 hours. Nylas commits to data privacy by using pseudonyms and minimizing data processing while actively monitoring US privacy laws, which lack a comprehensive federal equivalent to GDPR but include various sector-specific regulations. The company aims to prioritize privacy while providing secure communication APIs, ensuring compliance with evolving regulatory standards.
Mar 05, 2018
820 words in the original blog post.