Login

Search for suppliers

Search

News

Your marketplace has changed colours!

>> In 2008, SourcingParts is now MFG.com
>> Version 12.11 is live: a warm welcome to our Turkish manufacturers
>> A new organisation at your service
Click here for further information

Security Measures - Our Top Priority

Ensure that your data is never compromised

We know that security is crucial to you — that's why security is our top priority. We devote significant resources to continually optimize our world-class security infrastructure. The result: unsurpassed security and privacy for our customers' information.

Among other security measures, SourcingParts provides

  • Experienced, professional engineers and security specialists dedicated to round-the-clock data and systems protection.
  • Continuous deployment of proven, up-to-date security technologies, including proprietary products developed for SourcingParts
  • Ongoing evaluation of emerging security developments and threats.
  • Complete redundancy throughout the entire SourcingParts online infrastructure.
  • Client Auditing (Notably in the sectors of Aero-Defense).
Security Details Description
Physical Security
Our production equipment is collocated in Geneva, Switzerland at a facility that provides 24-hour physical security, palm print and picture identification systems, redundant electrical generators, redundant data center air conditioners, and other backup equipment designed to keep servers continually up and running.
Perimeter Defense
The network perimeter is protected by multiple firewalls and monitored by intrusion detection systems — all sourced from industry-leading security vendors. In addition, SourcingParts monitors and analyzes firewall logs to proactively identify security threats. SourcingParts also contracts with a third-party security firm that proactively monitors our security configurations for changes, vulnerabilities, and errors and regularly conducts vulnerability threat assessments including penetration tests.
Data Encryption
SourcingParts leverages the strongest encryption products to protect customer data and communications, including 128-bit Verisign SSL Certification and 1024-bit RSA public keys. The lock icon in the browser indicates that data is fully shielded from access while in transit.
User Authentication
Users access SourcingParts only with a valid username and password combination, which is encrypted via SSL while in transmission. Users are prevented from choosing weak or obvious passwords. An encrypted session ID cookie is used to uniquely identify each user. For added security, the session key is automatically scrambled and re-established in the background at regular intervals.
Application Security
Our robust application security model prevents one SourcingParts customer from accessing another's data. This security model is reapplied with every request and enforced for the entire duration of a user session.
Internal Systems Security
Inside of the perimeter firewalls, the systems are safeguarded by network address translation, port redirection, IP masquerading, non-routable IP addressing schemes, and more. The specific details of these features are proprietary.
Operating System Security
SourcingParts enforces tight operating system-level security by using a minimal number of access points to all production servers. We protect all operating system accounts with strong passwords, and production servers do not share a master password database. All operating systems are maintained at each vendor's recommended patch levels for security and are hardened by disabling and/or removing any unnecessary users, protocols, and processes.
Database Security
Whenever possible, database access is controlled at the operating system and database connection level for additional security. Access to production databases is restricted to a limited number of points, and production databases do not share a master password database.
Server Management Security
All data entered into the SourcingParts application by a customer is owned by that customer. SourcingParts employees do not have direct access to the SourcingParts production equipment, except where necessary for system management, maintenance, monitoring, and backups. SourcingParts does not utilize any managed service providers. The SourcingParts systems engineering team provides all system management, maintenance, monitoring, and backups.
Reliability and Backup
All networking components, SSL accelerators, load balancers, Web servers, and application servers are configured in a redundant configuration. All customer data is stored on a database served by a database server cluster for redundancy. All customer data is stored on carrier-class disk storage using RAID disks and multiple data paths. All customer data, up to the last committed transaction, is automatically backed up to a primary tape library on a nightly basis. Backup tapes are immediately cloned to verify their integrity, and the clones are moved to secure, fire-resistant, off-site storage on a regular basis.