選擇我們的理由

信任中心

誠信是 SailPoint 一切工作的基石。我們致力於維護您的信任並保護您的資料安全。

概覽

您的資料安全是我們的首要任務

在 SailPoint,我們的首要任務是確保客戶資料安全並遵守業界標準。SailPoint 採用符合業界慣例的公司治理政策與程序,以遵守我們業務所在各司法管轄區的適用法律和規章。

我們的品牌建立在「四個 I」理念之上:創新 (Innovation)、誠信 (Integrity)、影響力 (Impact) 和個人 (Individuals)。這些核心價值不僅塑造了公司的文化,也融入了我們的商業實務。我們以信守承諾,確保服務可靠安全為傲。最重要的事情莫過於保護客戶資料安全,並對我們的資料安全計畫保持透明。

我們在組織、架構和營運層面採用嚴格的安全措施,以確保客戶資料安全可靠。

SailPoint 的信任中心將您連接到我們的網路安全、法規遵循和隱私權計畫,讓您獲得管理資料所需的所有資訊。


AI

負責任地建構:我們致力於開發值得信賴的 AI

AI 是 SailPoint 身分安全解決方案的核心。我們並非該領域的新手,近十年,我們一直致力於幫助客戶充分利用 AI 的力量。這些年來,我們始終專注於客戶最關心的事情:信任。

從設計到部署,我們建構了以負責任、公正且可歸責的 AI 應用為中心的強大基礎架構。秉承以人為本的原則,我們的 AI 旨在增強人類的能力和決策能力,同時尊重人類的基本價值觀。
身為該領域的創新者和領導者,我們不僅開發了尖端解決方案,還獲得突破性進展的專利。這些專利彰顯了我們致力於突破 AI 創新極限,同時始終堅定不移地專注於信任、隱私權和安全的承諾。

在 SailPoint,我們不僅建立 Ai,我們建立值得您信賴的 AI。

網路安全

專為提供最佳防護而打造的架構

SailPoint 雲端專為支援最嚴格的安全控制而設計。透過威脅偵測與回應以及威脅暴露管理通訊協定,我們堅持最佳實務,實施嚴格的需求分析、設計測試與審核,以及強大的工程技術。透過符合業界基準和國際監管機構標準的政策和程序,進一步強化這些通訊協定。

SailPoint 透過安全軟體開發生命週期計畫來維護產品安全,主動識別並修復軟體中的漏洞。此外,外部安全研究人員也會審查我們的安全系統。

法規遵循

產品驗證

做為一個專注於安全的組織,SailPoint 實施嚴格的法規遵循標準,以確保我們的服務符合認證要求,並幫助我們的客戶遵守其所在行業的規章。

深入瞭解

Filters

SOC 1

SOC 1 (System and Organization Controls) is a report on controls at a service organization relevant to a entity’s control over financial reporting.

Learn more

Copies of SailPoint's SOC 1 Report can be made available to current customers and qualified prospects with a valid confidentiality agreement.

Please email [email protected] to request the latest SOC 1 report.

SOC 2

SOC 2 (System and Organization Controls) is a regularly refreshed report that focuses on non-financial reporting controls as they relate to security, availability, and confidentiality of a cloud service.

Learn More

Copies of SailPoint's SOC 2 Report can be made available to current customers and qualified prospects with a valid confidentiality agreement.

Please email [email protected] to request the latest SOC 2 report.

SOC 3

SOC 3 (System and Organization Controls) is a regularly refreshed report that focuses on internal controls as they relate to security, availability, and confidentiality of a cloud service.

Learn more

SailPoint has published a SOC 3 Report for the following products:

SailPoint Identity Security Cloud

SailPoint IdentityIQ

SailPoint Access Risk Management Service

SailPoint Non-Employee Risk Management

For inquiries about the ISO certificate or SOC reports, contact us at [email protected].

IRAP

IRAP (Infosec Registered Assessors Program) ensures entities can access high-quality security assessment services. The Australian Signals Directorate is supporting higher standards for security assessments and training through the enhanced Infosec Registered Assessor Program (IRAP).

Learn More

IRAP Completion Reports are available for the following:

SailPoint Identity Security Cloud

Data Access Security

For inquiries about this report, contact us at [email protected].

ISO 27001:2022

ISO 27001 is specification for an information security management system (ISMS), which is a framework for an organization’s information risk management processes.

Learn More

Download the Certificate

For inquiries about the ISO certificate or SOC reports, contact us at [email protected].

ISO 27017

ISO/IEC 27017 is an information security standard that provides additional guidance for relevant controls specified in ISO/IEC 27002; implementing information security controls within a Cloud computing environment for organizations that have an ISMS (information security management system) in place.

Learn More

Download the Certificate

*ISO 27017 inclusion is denoted under the ISO scope on Page 2 of the Certificate.*

For inquiries about the ISO certificate or SOC reports, contact us at [email protected].

ISO 27018

ISO 27018 builds on the ISO 27001 information security management system (ISMS) with a focus on protecting personally identifiable information (PII) in public clouds.

Learn More

Download the Certificate

*ISO 27018 inclusion is denoted under the ISO scope on Page 2 of the Certificate.*

For inquiries about the ISO certificate or SOC reports, contact us at [email protected].

ISO 27701

ISO 27701 is a standard designed to help organizations responsibly manage and/or process PII through the implementation of a Privacy Information Management System (PIMS).

Learn more

Download the Certificate

For inquiries about the ISO certificate or SOC reports, contact us at [email protected].

FedRAMP

The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that provides a standardized approach to security and risk assessment, authorization, and continuous monitoring for cloud products and services. All cloud services in use by federal agencies must meet FedRAMP requirements at the appropriate impact level (Low, Moderate, or High).

Learn More

Please visit our listing on the FedRAMP Marketplace.

For FedRAMP-related inquiries, contact us at [email protected].

C5

The Cloud Computing Compliance Controls Catalog (C5) is a German framework created by the German Federal Office for Information Security (BSI) which specifies minimum security requirements for cloud services.

Learn more

Copies of SailPoint's C5 Report can be made available to current customers and qualified prospects with a valid confidentiality agreement.

Please reach out to your Customer Success Manager or Sales Representative for more information.

Common Criteria

Common Criteria (CC), also known as ISO/IEC 15408, is an international standard for evaluating and certifying the security features of information technology products and systems, providing a framework for ensuring that products meet specific security requirements.

Learn More


SailPoint Common Criteria Certificates can be found on the Common Criteria Certified Product Listing:

SailPoint IdentityIQ

SailPoint File Access Manager

For Common Criteria-related inquiries, contact us at [email protected].

CSA STAR Level 1

The Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) Level 1 is a publicly accessible registry that documents the security and privacy controls provided by popular cloud computing offerings. This self-assessment demonstrates our commitment to transparency and adherence to industry best practices in cloud security.

Learn More

Please visit our listing on the CSA STAR Registry.

For CSA STAR-related inquiries, contact us at [email protected].

GovRAMP

StateRAMP (dba GovRAMP) is the leading authority on cloud security standards for federal, state,and local government organizations, providing a standardized approach to assessing and authorizing cloud services. GovRAMP empowers the public sector and their vendors to navigate the complexities of cloud security with confidence.

Learn more

Please visit our listing on the GovRAMP Authorized Product List.

For GovRAMP-related inquiries, contact us at [email protected].

深入瞭解

隱私優先的資料保護和信任方法

在 SailPoint,我們致力於尊重您的隱私。我們深知,當您選擇分享個人資訊時,您信任我們會以負責任的方式保護並安全管理這些資訊。我們將隱私置於首位,並將其融入我們的產品和服務,確保在滿足客戶期望的同時,遵守不斷演進的規章。瞭解更多關於我們隱私權和資料保護的資訊。