Security
Last Updated: October 31, 2022
Sona Labs (Sona) is committed to keeping your data safe and secure. Sona adheres to industry-leading security and privacy standards to ensure your data is safe and secure when collecting data, replicating data, loading data, and connecting to all of your data sources. Security practices are deeply ingrained into our internal software development, operations processes, and tools. These practices are strictly followed by our cross-functional teams to help prevent, detect, and respond to incidents in an expedient manner. We regularly incorporate advanced security techniques into the products and services we offer.
Please contact [email protected] if you have any questions or comments.
About the Sona Platform
The Sona Platform (SRG Platform) makes revenue attribution and planning easy for B2B marketers so they can understand how their marketing efforts are driving revenue. By unifying online marketing interactions, ad data, and CRM data with sales outcomes, marketers can gain actionable insights related to making data-backed optimizations. From first touch to sales and beyond, across all marketing channels, the SRG Platform enables marketers to connect marketing to revenue through advanced analytics.
Solution Architecture
Three primary components track, organize, and house data:
- The Sona Tracking Script (sona.js) captures all online marketing interactions, also called touchpoints, that prospects/leads have with the customer's organization. Includes a custom script added before the closing tag on every marketing page. Sona.js captures web visits (including anonymous), general traffic/page navigation, content downloads, and form submissions. The platform processes this data and pushes it into customer relationship management (CRM) solutions, displaying each interaction as an online touchpoint.
- Sona Platform Application — Customers use this to view and report on attribution data, configure account settings, and update account information.
- Sona Data Warehouse — All data generated by the Sona Platform Application is stored in an Elasticsearch cluster.
Data Connectors Include
- CRM and Data Warehouse Integrations — The SRG Platform integrates with CRM solutions to relay and organize processed data from the Sona Data Warehouse. Current integrations are listed on the Sona website.
- Third-Party Applications — The SRG Platform integrates with third-party marketing automation, ad platforms, A/B testing, analytics, and live chat applications. A current list is available on the Sona website.
Tracking Script Connectivity
- All connections to Sona's tracking servers are encrypted by default using industry-standard cryptographic protocols (TLS 1.2+).
- Any attempt to connect over an unencrypted channel (HTTP) is redirected to an encrypted channel (HTTPS).
- To take advantage of HTTPS, your browser must support encryption protection (all versions of Google Chrome, Firefox, and Safari).
Data Connectors
- Connections to customers' ad platform sources and destinations are SSL encrypted by default.
- Connections to customers' database sources and destinations are SSL encrypted by default.
- Sona can support multiple connectivity channels.
- Connections to customers' software-as-a-service (SaaS) tool sources are encrypted through HTTPS.
Data Flow Narrative
The following steps describe how data flows in a SRG Platform implementation:
- When a visitor lands on a customer's website with the script tag referencing sona.js, the visitor's browser makes a request to Sona's servers. This request includes standard information about the user's machine configuration, the page they are viewing, and pre-defined information the customer wants to track.
- Throughout the visitor's web session, the Sona client-side code relays tracked information to the SRG Platform Server using HTTPS.
- The SRG processing platform periodically queries external integrations (e.g., CRM, ad providers) for any updates since the last synchronization point.
- These updates are applied to SRG Platform customer-specific data in the segregated client data store.
- The SRG processing platform updates touchpoint and attribution data based on configuration settings stored in the SRG client configuration. Results are stored in the segregated client data store.
- If the customer has purchased the data warehouse add-on feature, some data in the segregated client data store is exported into an external data warehouse as specified by the client.
SRG Platform Portal Connectivity
- All connections to Sona's web portal are encrypted by default using industry-standard cryptographic protocols (TLS 1.2+).
- Any attempt to connect over an unencrypted channel (HTTP) is redirected to an encrypted channel (HTTPS).
- To take advantage of HTTPS, your browser must support encryption protection (all versions of Google Chrome, Firefox, and Safari).
Hosting and Security
The SRG Platform solution is hosted at data centers managed by DigitalOcean, LLC, with United States corporate headquarters located in New York City, NY. Sona cloud service infrastructure partners maintain very strict controls around data center access, fault tolerance, environmental controls, and network security. Only approved, authorized Sona employees, cloud service provider employees, and contractors with a legitimate, documented business need are allowed access to the secured sites.
Sona operates services in the United States, Netherlands, United Kingdom, Canada, and Germany:
| Datacenter | Region |
|---|---|
| NYC1 | New York City, United States |
| NYC3 | New York City, United States |
| AMS3 | Amsterdam, the Netherlands |
| SFO3 | San Francisco, United States |
| LON1 | London, United Kingdom |
| FRA1 | Frankfurt, Germany |
| TOR1 | Toronto, Canada |
Note: Sona also operates services in the SFO2 legacy datacenter in the San Francisco, United States region.
Segregated Client Data
Each customer's data is stored in a dedicated Digital Ocean storage account and a dedicated Elasticsearch schema. The only access to these servers and databases is via secure access by the application. All other access to the application and content servers is made only by authorized Sona personnel and is conducted via encrypted channels over secure management connections.
Data Availability
SRG Platform data is stored in a combination of Digital Ocean cloud repositories and Elasticsearch databases. Digital Ocean repositories provide their own redundancy mechanisms, offering "99.999999999% (Eleven 9's) durability over a year." SRG Platform data in Digital Ocean is stored in GRS storage, which is replicated in a cross-region manner.
Disaster Recovery
The SRG Platform is hosted on Digital Ocean continuously active Availability Zone (AZ) data center configurations. All Digital Ocean data centers are highly resilient, designed to deliver high availability and tolerate system or hardware failures with minimal impact. Each data center runs on its own physically distinct and independent infrastructure to help ensure business continuity in the event of an outage.
Availability and Notification
For both planned and unplanned system downtime, the SRG Platform team follows a notification process to inform customers about service status. If there is a need to migrate operational service from a primary site to a disaster recovery site, Sona can send customer-specific notifications, including:
- Notification of the intent to migrate services to the disaster recovery site.
- Throughout the visitor's web session, the Sona client-side code relays tracked information to the SRG Platform Server using HTTPS.
- Hourly progress updates during service migration.
- Notification of completion of the migration to the disaster recovery site.
Company Policies
- Sona requires that all employees comply with security policies designed to keep any and all customer information safe, and address multiple security compliance standards, rules and regulations.
- Two-factor authentication and strong password controls are required for administrative access to systems.
- Security policies and procedures are documented and reviewed on a regular basis.
- Current and future development follows industry-standard secure coding guidelines, such as those recommended by OWASP.
- Networks are strictly segregated according to security level. Modern, restrictive firewalls protect all connections between networks.
Cookie Preferences Management
Notwithstanding anything else in this Privacy Policy, Sona and marketing partners may use IP address, browser information, and device information obtained when visitors use the Site, utilize Services, or open messages sent by Sona, in conjunction with third-party web cookies, pixels, or similar technologies, enabling the company to obtain personal data about individuals (such as name, contact details, location, and employer) held by third parties. To opt out of the specific data collection and sharing practices described, please contact using the contact information set forth in the Privacy Policy section entitled "Privacy Questions."
In the Event of a Data Breach
To date, Sona has not experienced a breach in security of any kind. In the event of such an occurrence, Sona protocol is such that customers would be made aware as soon as the compromise is confirmed.