Physical Security Overview
Infrastructure Hosting & Management
Pneumatic’s infrastructure is securely hosted on and managed by Google Cloud. This partnership leverages Google’s state-of-the-art data center technology and management, ensuring high levels of reliability and compliance with industry standards. Google is recognized globally for its risk management capabilities and adheres to standards such as ISO 27001, SOC 1 and 2, PCI Level 1, FISMA Moderate, and SOX.
On-site Security Measures
The physical security of our data centers, certified under ISO 27001 and FISMA, includes military-grade perimeter controls, natural boundaries, and nondescript building designs to prevent unauthorized access. Access control is enforced rigorously through professional security guards, surveillance cameras, and advanced intrusion detection systems. Authorized staff undergo multi-factor authentication multiple times for data center access, while visitors are escorted at all times.
Data Center Locations
Our data centers are strategically located within the United States (Oregon) to optimize performance and security.
Network Security Protocols
Security Response Team
A dedicated team is on standby to address security concerns, reachable via security@pneumatic.app.
Firewall Management
Our network is protected by Google Cloud’s firewall systems, which govern access based on specific business needs and security policies. This includes host-based firewalls for added protection and measures to prevent spoofing and sniffing attacks.
Vulnerability Management
Regular security assessments by specialized software platforms ensure ongoing security improvements. Our infrastructure is designed to prevent unauthorized access, including packet sniffing and port scanning, with every incident being thoroughly investigated.
Penetration Testing and Vulnerability Assessments
Our service provider is security-tested by independent security firms on a regular basis. Findings of all such assessments are reviewed with the assessors, all identified risks are ranked and action is taken to minimize them.
Incident Response
In the event of a security incident, our engineers analyze extensive system logs to address and mitigate the issue promptly.
DDoS Mitigation
Our service provider (Google Cloud) employs advanced DDoS mitigation techniques, such as TCP Syn cookies and connection rate limiting, to protect against denial-of-service attacks.
Logical Access
Production network access is tightly controlled and audited, with multi-factor authentication required for all staff.
Encryption and Authentication
Data Transfer Encryption
CSP-managed (default) data encryption is applied. Our email service ensures secure TLS connections.
Data storage and backup
Backups are automatically created daily between 3 AM – 7 AM UTC, with a limit of 7 backups.
Data Encryption at rest
Data encryption at rest (CSP-managed default encryption type). Use of customer-managed encryption keys (CMEK) is possible but not applicable to SSD storage type with this CSP.