Tidepool employs Infrastructure and service providers in the form of Infrastructure as a Service (IaaS) and Database as a Service (DBaaS) using Amazon Web Services and MongoDB Atlas as our main providers for our application, https://app.tidepool.org .
Tidepool received our SOC 2 Type II clearance from Prescient Assurance and is under audit for yearly SOC 2 Type II going forward. A gap letter will be available to provide assurance that controls and systems continue to be audited and verified.
Access to Tidepool’s SOC 2 reports, Penetration Test, or other sensitive documentation under NDA is available via our Conveyor Trust Portal profile.
We are also regularly asked to provide compliance certification for all of our providers. In many circumstances, providers have indicated that without a Non Disclosure Agreement (NDA), these documents may not be provided by us directly to assessors who are not customers of the service.
To assist IT Organizations in assessing compliance risk for Tidepool’s use of these service providers, we recommend personal verification that AWS and MongoDB Atlas are compliant if required.
Tidepool validates our sub-processors and service providers are compliant during an initial Service/Software Integration Review prior to implementation and annually as part of our Risk Management and Vendor Management programs.
We last performed an annual review
All vendors are reviewed by Tidepool Security for:
Security Compliance Certification
Data Residency (must reside in US)
Terms of Use and Privacy Policy
Authentication and Authorization
Integration points with any Tidepool infrastructure
Network and Application Security controls
Logging and Auditing Controls
Amazon Web Services (AWS)
We annually validate that AWS is certified and accredited