17 June 2021: Important security improvements

Neelke Stadler Updated by Neelke Stadler

Security is always top of mind for us. We made a number of improvements that we'd like you to know about.

Security improvements relevant to all customers:
  • All error logs are now scrubbed to remove sensitive (i.e. personal identifiable information) data and message content. It will be an ongoing effort to ensure all sensitive data is identified and scrubbed sufficiently. We do this to ensure that in the event of technical things going off-beat no unnecessary user information lies around. Personal information should only ever be available and used for its intended purpose.
  • Automatic time based message data scrubbing is now available on a limited basis, get in touch if you are interested to find out more or make use of this. This allows you to permanently delete user data to be inline with internal policy or regional legislation.
Security updates specific to Private Clouds installations:
  • Access to the Turn web application and API can now be restricted to specific IPs. By default the Turn web application and API for Private Cloud installations is accessible to any clients on the public internet. By restricting access to specific IPs Private Cloud installations can enjoy added security by allowing only whitelisted client IPs on the public internet to access the web application and API.
  • Encryption at rest is now enabled for all existing and new installations for Turn media assets stored in S3. This ensures that data would not be accessible should the underlying storage device be compromised, lost or otherwise improperly disposed of.
  • Encryption at rest is now enabled for all new installations for WhatsApp attachments stored in EFS. This ensures that data would not be accessible should the underlying storage device be compromised, lost or otherwise improperly disposed of.
  • Lastly, you will now be automatically notified via email when AWS IAM or Security Group changes are observed. This helps you to be kept abreast of user and security related changes.

That's it for now! There are always a bunch of technical work happening behind the scenes that are more technical difficult to explain in layman's terms but we wanted to highlight these updates so that you know security is important to us, always.

Was this article helpful?

21 June 2021: Sample content for templates

8 June 2021: Community Playbooks

Contact