Security

Cloud Services Security

How we protect the confidentiality, integrity and availability of the solutions we host on AWS.

Overview

The FM Studio is committed to excellence - both of its service offerings and how it serves its valued clients. Our service offerings are designed to help clients make their business better through high-performance, secure, and highly available solutions. And The FM Studio values trust.

To demonstrate this, we have consistently applied industry-leading security practices to our own operations, including incorporating the Claris® | FileMaker best-practices security guide recommendations for configuring our Cloud Services environment. These have been designed to embody the latest security standards and protocols, and are maintained with the latest updates and security patches.

Our Cloud Services production infrastructure is provided by Amazon Web Services (AWS). AWS data centres and AWS services deliver the physical infrastructure, environmental controls, access-control mechanisms, and monitoring systems that enable the highly secure and highly available offerings from The FM Studio.

Through our relentless commitment to excellence and our relationship with AWS, The FM Studio is able to provide enterprise-grade offerings to organisations of all sizes in its pursuit of enabling digital transformation.

Security governance

Security and control environment

The FM Studio team is responsible for ensuring the confidentiality, integrity, and availability of all of its clients' hosted solutions managed by them. This includes all information within AWS facilities, on equipment, or transiting networks owned by or in direct partnership with AWS. Specific methods used to achieve these objectives include, but are not limited to: development and distribution of security policies and procedures, security assessments, monitoring and processing of security alerts, and responding to security incidents.

People, policies, and training

The FM Studio employs individuals of long standing who are certified professionals in their discipline and are committed to the key principles of honesty, respect, confidentiality, and compliance.

The FM Studio maintains a set of policies, standards, and guidelines to serve as the body of requirements for implementing highly secure and highly available systems, based on the Claris® | FileMaker best-practices security guide and policies set out by AWS. Key personnel are required to complete annual security awareness training, and those with responsibilities that impact the security of our service offerings receive additional training on a variety of topics.

Technical security

The FM Studio leverages global security frameworks to guide its security processes and controls. Key topics such as physical security, authentication, encryption, network security, and system hardening are detailed below.

Physical security and environmental controls

The FM Studio uses AWS for its hosting needs. AWS has obtained a SOC 2 Type II certification over the services used by The FM Studio, including the physical and environmental security control of its data centres. AWS has security controls to limit physical access to its facilities and critical systems, including a proximity badge access system, biometric readers, facility camera systems, and visitor logs.

Authentication controls

The security of The FM Studio's systems, devices, and accounts starts with secure credential creation and management. Administrative access to our hosting environments is limited to administrators through multi-factor authentication. Within the environment we deploy the concept of least privilege - through role-based access control features within AWS, we provide highly granular permissions to different types of administrators (e.g. server administration, database administration, network administration). Our service offerings support authentication via external identity providers including Apple Open Directory and Microsoft Active Directory.

OAuth 2.0 is used to authenticate users who sign in to custom apps via a third-party identity provider such as Amazon, Google, or Microsoft Azure. The latest versions of FileMaker also support OpenID.

Administration - the FileMaker Server Admin Console

The FileMaker Server Admin Console is a web application for working with custom apps hosted by The FM Studio and for managing FileMaker Server. It allows authorised administrators to:

  • Monitor server statistics (CPU, memory, network usage and disk space).
  • Manage database files (open, pause, close, download, remove, verify).
  • Disconnect and message idle users.
  • Schedule backups (auto-backup and on-demand, preserved and scheduled backups of solutions).
  • Configure general settings including FileMaker clients, folders, server-side scripts and notifications.
  • Manage SSL certificates and logging.
  • Manage connectors for Web Publishing, the FileMaker Data API, plug-ins, and ODBC/JDBC connectivity.
  • Administer the server (management of FileMaker licences, administrator credentials and external authentication).

Data encryption

Protecting sensitive information is deeply embedded in The FM Studio's DNA. Encrypting data in transit and at rest is one of the primary tools we employ as a key part of our commitment to clients.

  • In transit: client connections require the use of the TLS 1.2 protocol.
  • At rest: FileMaker Server utilises several AWS data storage environments for data persistence. Across these platforms we use AWS Key Management Service (KMS) for the encryption of data at rest.
  • Disk: we leverage AWS KMS with AES 256-bit encryption.

Network security

Firewalls are an important part of any security effort. The FM Studio leverages firewalls throughout the network and between different zones, including application firewalls, web application firewalls, and network-layer firewalls. Network traffic is continuously monitored (AWS CloudWatch).

System hardening

Hardened baseline configurations help drive consistency within the operational environment and provide assurance that systems are built using approved software, while minimising the attack surface. AWS Information Security-approved tools for malicious software detection are default requirements within configuration baselines, providing system-level detection, monitoring, and alerting of potential security events.

Security assessments and vulnerability management

Security assessments, performed by the Claris FileMaker Information Security Team, are performed before production deployments of new or updated features, services, configuration, or code changes. Security testing of infrastructure, including network devices and operating systems, is supported through vulnerability scanning and subsequent remediation.

Business continuity & disaster recovery

The FM Studio uses AWS for its hosting infrastructure needs. AWS has architected its environment to be highly redundant and to provide high availability to its customers. Additionally, The FM Studio leverages AWS's ISO 27001 certification process, and the data centres of AWS are audited for resiliency and continuity of operations.

Data management & privacy

Data retention

The FM Studio has retention policies and schedules to outline the required retention periods for records. Clients' hosted solutions are available for 30 days after the termination or expiration of a client's Cloud & Managed Services subscription, after which all such systems are deleted. Client data used to manage user administration (name, email, and phone number) is retained at the discretion of the client and in compliance with our Privacy Policy.

Privacy

The FM Studio is committed to customer privacy and complies with applicable privacy regulations in regards to our service offerings. We collect only the minimum amount of data necessary to provide customers with the services, and customer data collected is treated at all times in accordance with our Privacy Policy.