GrowSurf Security

Protecting and securing data at GrowSurf is our top priority.

Infrastructure

Infrastructure

System architecture

GrowSurf’s architecture is designed to be secure and reliable.

GrowSurf uses firewalls, IP allowlists, load balancers, and Cloudflare to protect and route network traffic. DigitalOcean and Google Cloud Platform provide cloud infrastructure, and SigNoz provides application monitoring and logging.

Services are accessible only to other services that require access. Access keys are rotated regularly and stored separately from code and data.

Data centers

GrowSurf’s production application infrastructure and managed MongoDB are hosted in DigitalOcean’s SFO2 datacenter (San Francisco, United States). Firebase Realtime Database is hosted in Google Cloud’s us-central1 region (Iowa, United States).

Vulnerability scans

GrowSurf uses security tools to continuously scan for vulnerabilities. Additionally, vulnerabilities in third-party libraries and tools are monitored and software is patched or updated promptly when new issues are reported.

Firewall

Our servers are protected by firewalls and not directly exposed to the Internet.

Corporate network

GrowSurf runs a zero-trust corporate network. There are no corporate resources or additional privileges from being on GrowSurf’s corporate network.

Data

Data

Data storage

GrowSurf data stores are accessible only by services that require access. Production and non-production environments are separated. GrowSurf’s production application infrastructure and managed MongoDB are hosted in DigitalOcean’s SFO2 datacenter (San Francisco, United States). Firebase Realtime Database is hosted in Google Cloud’s us-central1 region (Iowa, United States). Other service providers may process data in the locations disclosed in our subprocessor list.

Backups

GrowSurf maintains daily disaster-recovery backups. Managed MongoDB backups are retained for 7 days, and Firebase Realtime Database exports are retained for up to 30 days. Deleted data may remain in encrypted, access-restricted backups until expiration, but is placed beyond use and is not processed for ordinary business purposes. If a backup is restored, applicable deletion instructions are reapplied before the data returns to ordinary use.

Logs

We aggregate logs to secure encrypted storage. All sensitive information (including passwords, API keys, and security questions) is filtered from our server logs.

Processing

GrowSurf processes data only to fulfill its obligations as related to the Services outlined in our Terms of Service. All personal information for GrowSurf users and participants are shared to the minimal extent. Please see section HOW AND WHY WE USE YOUR PERSONAL INFORMATION in our Privacy Policy

Sharing with third parties

We only share data with the vendors listed in the subprocessors section on the GrowSurf GDPR Portal.

Breaches

Our internal GDPR and CCPA Compliance processes cover protocols for data breaches, user policies, and more.

Tax identification data

If you enable Tax Reporting, full tax identification numbers (SSN/EIN/TIN) and signed W-9/W-8 forms are collected and stored by our tax-filing provider, TaxBandits — not by GrowSurf. GrowSurf retains only the last four digits plus the limited tax metadata required for 1099 filing.

Authentication

Authentication

Passwords

We never store passwords in a form that can be retrieved. Instead, we store an irreversible cryptographic hash using a function specifically designed for this purpose. Authentication sessions are invalidated when users change key information and sessions automatically expire after a period of inactivity.

Monitoring

We monitor and rate limit authentication attempts on all accounts.

User roles

We provide multiple user roles with different permissions levels within the product. Roles vary from account owners, to admins, users, and roles that limit visibility of Personally Identifiable Information (PII).

Encryption

Encryption

HTTPS

GrowSurf’s web app and REST API are served over HTTPS and use HSTS.

Encryption

We encrypt all data in transit over the HTTPS network protocol.

Certain sensitive information such as third-party API keys and Webhook secrets are encrypted at rest via AES-256.

Policies

Policies

Policies

GrowSurf has developed a comprehensive set of security policies covering a range of topics. These policies are updated frequently and shared with employees.

Topics include, but are not limited to, general internal protocols, password and security/network policies for GrowSurf employees, including handling sensitive customer data.

Incident response

GrowSurf has a defined protocol for responding to security events.

Security training

All employees complete security training when they join and are continually refreshed.

Employee vetting

GrowSurf performs background checks on all new employees in accordance with local laws. The background check includes employment verification and criminal checks for US employees.

Confidentiality

All employees have signed confidentiality agreement with GrowSurf.

PCI compliance

All credit card payments paid to GrowSurf go through our payment processing partner, Stripe. Details about their security posture and PCI compliance can be found at Stripe’s Security page.

Disclosure

If you have any concerns or discover a security issue, please contact us directly. Our Security team will acknowledge receipt of each vulnerability report, conduct a thorough investigation, and then take appropriate action for resolution. We request that you do not publicly disclose any issue you discovered until after we have addressed it.

Other

Other

Business continuity process

Our internal Business Continuity Process (BCP) outlines protocols in the event of a disruption to normal operations.

Disaster recovery process

Our internal Disaster Recovery Process (DRP) outlines protocols to restore data in the event of disasters.

Security questionnaire request policy

Please note, GrowSurf only accomodates security questionnaire requests, modified DPA requests, or any other legal/vendor requirements for customers on our annual plans. If you have bespoke legal and compliance needs, please get in touch with sales.
GDPRPowered by ComplyDog