Appsflyer Security Policies and Practices
Appsflyer Security Policies and Practices
Appsflyer Security Policies and Practices
and Practices
INTRODUCTION
At AppsFlyer, data security, scalability and performance are our
lifeblood. Our state-of-the-art real-time infrastructure, advanced
security and data protection, independent certifications and global
regulatory compliance have earned the trust of the world’s leading
brands.
We strive to implement the highest level security processes and
practices across all business units. To help ensure we attain this
goal, our staff includes a full-time, in-house chief information
security officer (CISO) and a growing dedicated security team.
PEOPLE
The teams behind AppsFlyer products play an essential part in protecting
our service on an organizational level.
SECURITY TEAM
AppsFlyer’s business operation team includes top-notch security and privacy professionals who are experts in information, application and network
security. The team is tasked with:
AppsFlyer’s dedicated security team actively scans for security threats using commercial and custom tools, penetration tests, quality assurance (QA)
measures, and software security reviews.
Members of the AppsFlyer information security team review security plans for all networks, systems and services. They provide project-specific
consulting services to AppsFlyer’s product and engineering teams. They monitor for suspicious activity on AppsFlyer’s networks, address information
security threats, perform routine security evaluations and audits, and engage outside experts to conduct regular security assessments.
PEOPLE
HIRING
The AppsFlyer screening process is based on background checks and
personal interviews with recruitment/HR managers and hiring managers.
Where applicable, additional background checks are included based on
local law.
INFOSEC TRAINING
New employees go through an on-boarding process that includes
security guidelines, expectations, and code of conduct. All AppsFlyer
employees undergo annual security awareness training.
ONGOING COMMUNICATIONS
The AppsFlyer security team communicates with all employees on
a regular basis, covering topics such as emerging threats, phishing
awareness campaigns, and other industry-related security topics.
PRODUCT
APPLICATION SECURITY
The AppsFlyer security development lifecycle (SDLC) standard helps ensure the delivery of a highly secure platform.
The following activities help us achieve this mission:
SDLC
All products and features undergo
thorough security reviews and code
AppsFlyer Security Policies and Practices scanning. 6
APPLICATION SECURITY
ACCOUNT SECURITY
MONITORING AND VISIBILITY
PRODUCT
ACCOUNT SECURITY
AppsFlyer provides the most thorough authentication security measures in the mobile attribution industry. Among the available authentication
capabilities, many settings are fully configurable to suit individual organizational standards and needs.
PRODUCT
ACCOUNT SECURITY
Self-serve
PRODUCT
MONITORING AND VISIBILITY
Our security team continuously monitors and assesses compliance,
regulation and risk. Our vulnerability tests establish how we identify,
respond, and triage vulnerabilities against the AppsFlyer platform. To
ensure the security of our platform, AppsFlyer continues to improve and
enhance its security capabilities: Continuous 24/7/365 monitoring and the
implementation of a variety of security tools and other components to
detect and mitigate any new vulnerabilities, incidents, and threats.
CLOUD
The security of our infrastructure and networks is critical. Creating a
safe platform for AppsFlyer application and customer innovation is the
mission of our cloud security.
BUSINESS CONTINUITY
While we can’t predict the future, we can ensure that we are fully
prepared for it. That includes managing potential service interruptions
and minimizing recovery time.
DATA
DATA IN TRANSIT
Data is vulnerable to unauthorized access as it travels across the internet
or within networks. For this reason, securing data in transit is a high priority
for AppsFlyer. Our web servers support strong encryption protocols to
secure connections between customer devices and AppsFlyer’s web
services and APIs. Any traffic transferred to AppsFlyer encrypted over
https using TLS1.2 only.
DATA AT REST
Data is encrypted in our databases using AES256bit encryption by default.
DATA
MASKING
Our customers can choose to implement even stricter security measures, i.e., additional layers of protection to their account. We encourage customers
to work with their account managers to make sure any specific security needs are being met, such as IP masking.
THIRD PARTIES
Every organization relies on other organizations – whether its an email provider, a server farm or the cafe that caters your Friday lunches. Vendor
security must be addressed just like any other element in organizational security. Investing in internal security and ignoring the security vulnerability is
like padlocking your front door but leaving a window open. Vulnerability is just that, a vulnerability; and third-party vendors can be a significant one.
AppsFlyer is a 3rd-party vendor for some of the world’s biggest organizations. On top of that, AppsFlyer’s products have third-party integrations and we
employ vendors for internal services across multiple departments. We take 3rd party security as seriously as an other internal security measures:
in the industry.
ISO27032
ISO27701
CSA STAR
TRUSTe ePrivacyseal
AppsFlyer meets all the privacy requirements established by ePrivacy GmbH awards the data protection seal of approval following
TRUSTe and/or applicable regulatory bodies. Our continued an in-depth audit of a company's online and mobile products. The
TRUSTe certification demonstrates AppsFlyer's utmost certification covers the requirements of GDPR for digital products.
commitment to transparency. TRUSTe reviews our website and its Following a stringent evaluation process, AppsFlyer has been
subdomains, software development kit {"SDK"), and APl's. awarded the ePrivacyseal for compliance with all criteria outlined by
ePrivacyseal.