Production access
All Tidepool employees and subcontractors work remotely.
Some full-time Tidepool team members with privileged access reside outside of the United States. These international subcontractors are legally bound by the same confidentiality and security requirements as our US-based employees.
Tidepool employees with critical production access
Access to servers is limited, logged and audited and defined explicitly using Role Based Access Control (RBAC).
Employees accessing our production database or applications authenticate using two-factor authentication.
We do not allow SSH or RDP access (or any other direct access to production systems, including database).
All connectivity to backend systems takes place within an AWS VPC over authenticated private network connections.
Admin and support access roles:
RBAC via OpenID Connect and OAuth2 (Google SSO)
All admin actions occur via an API gateway over TLS with full auditing/logging
All access for monitoring and troubleshooting takes place over API, there is no back end
root
account.Application Security access changes are documented and approved via source code control
All login access to the AWS console requires two-factor authentication using a separated account (non-domain).
Use of access keys for service accounts is minimized via the use of IAM roles, with regular review and key rotation
Tidepool Employees Access Roles:
Full administrator access, including the production database (PHI): 7
Software deployment access for Tidepool Web
: 2
Software deployment access for Tidepool Uploader
: 2
Software deployment access for Tidepool Mobile
: 4
User Support access in ZenDesk
: 25
US Tidepool employees may provide user support and have access to end user account conversations in a support capacity. These conversations may include discussion of PHI.
User support access in Tidepool Web
: 14
Tidepool Web allows users to share account data directly with Tidepool within the application to assist with technical support questions and troubleshooting.
The content of the Tidepool Technical Documentation is licensed under a Creative Commons CC0 1.0 Universal (CC0 1.0) Public Domain Dedication.