EvenUp | Trust Center
EvenUp Trust Center
Our mission is to level the playing field in personal injury cases. We believe that every injury case deserves to be settled based on its true merit. This page is designed to provide you with transparency and information about how we handle your data, the measures we take to safeguard it, and our compliance with relevant regulations and industry standards.
Compliance
SOC 2 Type 2
Request
HIPAA
Request
CCPA
Request
Monitoring
Continuously monitored by Secureframe
Change Management
- Software Change Testing
- Baseline Configurations
- Approval for System Changes
Availability
- Testing the Business Continuity and Disaster Recovery Plan
- Uptime and Availability Monitoring
- High Availability Configuration
Organizational Management
- Advisor Meetings on Security
- New Hire Screening
- Information Security Program Review
Confidentiality
- Retention of Case Data
- Deletion of Case Data
Vulnerability Management
- Third-Party Penetration Test
Incident Response
- Lessons Learned
- Tracking a Security Incident
- Incident Response Plan Testing
Risk Assessment
- Risk Assessment
- Vendor Risk Assessment
- Vendor Risk Management Policy
Network Security
- Endpoint Security
- Network Traffic Monitoring
Access Security
- Administrative Access is Restricted
- Unique Access IDs
- User Access Reviews
Physical Security
Resources
If you would like to report a vulnerability, please contact security@evenup.ai with a proof of concept, list of tools used, and the output of the tools. Once received, EvenUp will work quickly to reproduce each vulnerability to verify its status before taking the steps needed to address it.
Vulnerability Disclosure
To report a vulnerability, contact security@evenup.ai with a proof of concept, list of tools used, and the output of the tools. Once received, EvenUp will work quickly to reproduce each vulnerability to verify its status before taking the steps needed to address it.
Monitoring
Change Management
- Software Change Testing: Software changes are tested prior to being deployed into production.
- Baseline Configurations: Baseline configurations and codebases for production infrastructure, systems, and applications are securely managed.
- Approval for System Changes: System changes are approved by at least 1 independent person prior to deployment into production.
Availability
- Testing the Business Continuity and Disaster Recovery Plan: The Business Continuity and Disaster Recovery Plan is periodically tested via tabletop exercises or equivalents.
- Uptime and Availability Monitoring: System tools monitor for uptime and availability based on predetermined criteria.
- High Availability Configuration: The system is configured for high availability to support continuous availability, when applicable.
Organizational Management
- Advisor Meetings on Security: Senior management and/or board of directors meets at least annually to review business goals and security risks.
- New Hire Screening: Hiring managers screen new hires to assess their qualifications and experience.
- Information Security Program Review: Management is responsible for the design, implementation, and management of the organization’s security policies.
Confidentiality
- Retention of Case Data: EvenUp retains case data in accordance with customer agreements and applicable requirements.
- Deletion of Case Data: Upon a valid customer request, EvenUp deletes case data based on the customer agreement.
Vulnerability Management
- Third-Party Penetration Test: A 3rd party conducts a network and application penetration test annually.
Incident Response
- Lessons Learned: After any security incident, a "Lessons Learned" document is provided to improve security.
- Tracking a Security Incident: Identified incidents are documented and tracked according to the Incident Response Plan.
Risk Assessment
- Risk Assessment: Formal risk assessments are performed to identify internal and external threats.
- Vendor Risk Assessment: New vendors are assessed in accordance with the Vendor Risk Management Policy.
Network Security
- Endpoint Security: Company endpoints are managed with a strong password policy and antivirus protection.
Access Security
- Administrative Access is Restricted: Access to production infrastructure is limited based on least privilege.
- Unique Access IDs: Personnel are assigned unique IDs for access to sensitive systems.
- User Access Reviews: Scheduled user access reviews are conducted to validate access based on job responsibilities.
- Removal of Access: Upon termination, system access is removed.