Security
Action1 uses security controls designed to protect customer data and maintain its integrity. These controls include continuous security monitoring, regular audits, encryption, access restrictions, and compliance processes.
Action1 has completed independent audits for SOC 2 Type II and ISO/IEC 27001:2022. To request the relevant audit reports, contact your Action1 representative.
Data Encryption and App Security
Endpoints connected to the Action1 Cloud communicate over encrypted channels. Action1 uses RSA-2048 keys to protect communications between the Action1 Cloud and managed endpoints. A private key is generated for each Action1 account and included in the Action1 Deployer and agent installation packages associated with that account.
Keep installation packages and account credentials secure to prevent unauthorized access to your Action1 environment.
Access to Action1 resources through the API is secured using OAuth 2.0.
Multi-Factor Authentication
Action1 supports multi-factor authentication (MFA) for access to the Action1 web console. MFA adds an additional verification step during sign-in and helps protect user accounts from unauthorized access.
Action1 recommends using app-based MFA with an authenticator application, such as Google Authenticator, Twilio Authy, Duo Mobile, or Microsoft Authenticator.
Alternatively, you can use email-based MFA by entering the one-time verification code sent to your email address.
For more information, refer to Multi-factor Authentication.
Password Expiration Interval
Use this advanced setting to specify how many days a password remains valid before the Action1 user is required to create a new one. The default value is 0 days (password never expires).
Configure this setting as part of your organization’s password policy, together with requirements for password strength, reuse, and account protection. Choose an expiration interval that aligns with your internal security standards and applicable compliance requirements.
See also: Appendix: Action1 Advanced Settings.
Compliance and Security Regulations
Action1 has completed independent audits for SOC 2 Type II and ISO/IEC 27001:2022.
Action1 also implements security controls and processes intended to support customers subject to requirements and frameworks such as PCI DSS, SOX, HIPAA, GDPR, and NIST.
Action1 applies the principle of least privilege to restrict employee access to corporate systems and customer data. Action1 personnel do not access your Action1 account or data unless access is required and explicitly authorized, for example, when investigating a support request.
Action1 is hosted on Amazon Web Services (AWS). For information about AWS security controls and compliance programs, see AWS Compliance Programs and AWS Cloud Security.
Recommendations for Protecting Your Data
Follow these recommendations to help prevent unauthorized access to your Action1 account and managed endpoints:
-
Lock your computer when you leave it unattended, and protect it with a password.
-
Enforce a strong password policy.
-
Use app-based MFA instead of email-based MFA when possible.
-
Use current antivirus and antimalware software.
-
Regularly install operating system and application security updates.
-
Use Action1 to identify missing updates and automate patch deployment. For more information, see Create a Patch Management Policy.
-
If you are a managed service provider or manage separate business units, create Organizations in Action1 to separate endpoints and control access to them. For more information, see Multi-Tenancy for MSPs and Enterprises.
Status
For information about Action1 service availability, scheduled maintenance, and service disruptions, see the Action1 Status page.