Data Security

Our firm was founded by cybersecurity and privacy researchers from IMEC-Distrinet research lab at the KULeuven, Belgium. Videolab has been developed by leveraging LINDDUN, a privacy by design methodology now part of the NIST Privacy Framework. Although GDPR compliance is a journey, not a destination, Videolab is as GDPR compliant as it can be.

Security Countermeasures

Videolab contains a wide range of security countermeasures. The most notable are mentioned on this page. Our complete security threat model and the data privacy impact assessment will be made available upon request.
secure-vault

Codific Secure Vault

Codific Secure Vault is a secure storage where all recordings are stored.

  • All data is encrypted using Industry-standard AES-256 encryption.
  • Encryption keys are stored in dedicated safety boxes each owned by a specific user.
  • The Vault master access is guarded by a two-man rule implementation based on strong cryptographic primitives.
  • All audit traces are stored in a so-called write-once read-many storage.
  • The Vault features a flexible access control policy management mechanism to enable secure sharing of data between multiple users. The policies themselves are also stored within the Vault.
penetration-test

Penetration testing

Codific’s internal Team Red as well as a number of third parties conduct periodic penetration testing of Videolab.

 

2fa

Multi-factor authentication

For all authorized access a multi-factor authentication mechanism is enforced.

patrol-monitoring

Monitoring

Secure Patrol is a complete solution targeted towards real-life monitoring and protection of software systems. Secure Patrol consists of a team of AI and human agents who patrol software systems preventing and intervening on possible attacks.

firewall

Application-Level Firewall

We deploy an application-level firewall to make sure malicious requests are blocked.

browser-security

Browser Security

We leverage best practices in browser security hereby reducing the likelihood and impact of various categories of attacks, such as Cross-Site Scripting, Injection, etc.

server-hardering

Server Hardening

Server hardening involves reducing the available ways to attack the server infrastructure where the Videolab web application is hosted.

auditing

Auditing

We conduct audits including a threat modeling analysis where new threats, their likelihood and impact are assessed regularly.

aplus-https

End-to-end encryption

All access to Videolab is secured using an A+ grade transport layer security.