LicenseSpring is deeply embedded in the products, revenue workflows, and licensing infrastructure of software vendors around the world. Because of this responsibility, security and data protection are foundational to how our platform is designed, built, and operated.
From ISO-certified development practices to continuous vulnerability monitoring and encrypted data management, LicenseSpring implements comprehensive security controls to ensure the confidentiality, integrity, and availability of the platform.
This security framework enables software vendors to confidently integrate LicenseSpring into mission-critical licensing, entitlement, and monetization workflows.
Our approach to security combines:
Secure Infrastructure for Modern Software Monetization
Kraken Systems ltd, the R&D Centre developing and maintaining the LicenseSpring service, has continuously obtained ISO certification since January 2020. The certificates can be viewed here: ISO27001 and ISO9001.
The process of obtaining ISO27001 has enabled us to implement policies and controls ensuring security, data confidentiality, integrity and availability of the LicenseSpring service. ISO9001 enabled us to develop and implement a structured approach to managing the quality of our products to increase our velocity and reduce waste and inefficiencies in our development processes. Recertifying both highlights our commitments to the security and quality standards as well as our commitment to continuous improvements, while aligning our development procedures to changing regulatory requirements while ensuring we are following industry best practices.
We maintain and periodically update an Information Security Policy as well as a patch management policy, which is reviewed at least once a year. We organize penetration testing conducted by a trusted third-party provider on critical parts of the LicenseSpring service at least once every calendar year and remediate any findings with priority set based on severity levels. Additionally, internally, as part of our CI/CD process, we conduct vulnerability scans using third-party services and remediate any findings with priority set based on severity levels. Our Operations team is responsible for overseeing all security functions.
In order to stay informed on the current information security threats, risks, vulnerabilities and trends, we follow industry standards, including guidance provided from CVE, ExploitDB, OWASP top 10, Mitre ATT&CK Framework updates; we also follow Gitlab and Snyk and NIST best practices.
All employees must go through security awareness training as part of their orientation as well as at least once per calendar year.
We strictly adhere to least privileges access principles. The separation of duties is enforced via automation of Identity and Access management, which enables us through SSO to control access to all internal systems and tooling. We use Role Based Access Control (RBAC) with Multi-Factor Authentication (MFA) enforced via SSO, making it straightforward to provision and revoke.
Logs are reviewed daily as part of routine Operations tasks. We log and monitor all systems that make up the SaaS environment, including but not limited to the following:
User logons/logoffs
System changes (starting / stopping services, installing applications etc.)
Admin/management activities
Access to sensitive data / files
Account creation/deletion/modification
Privilege changes on accounts
System errors and alerts
Any change to a production system or baseline configuration is first validated as having passed our QA process. We use a modern ticketing system to log and track all change requests.
Our Changelogs are published here: API changelog Platform changelog
We perform background checks on all employees, contractors and individuals prior to granting access to any systems, network or physical data center facilities. Background checks include Police Reports and extensive background checks for new hires. Vendors and suppliers are not provided access to the SaaS infrastructure, network, or physical data center facilities.
All sensitive data within the LicenseSpring SaaS infrastructure is encrypted with AES-256 encryption at rest (at the time of this writing). In-transit, data is https enforced.
Encryption keys are securely stored and managed by a Key Management System (KMS).
We have a comprehensive data loss prevention strategy in place and is periodically tested.
We have a formalized business continuity plan in place which has been approved by management, and is reviewed and updated at least once every calendar year. Full backups are taken several times a day as well as differential backups, enabling Point in Time Recovery (PITR). Backup testing is performed frequently.
We make best efforts to provide 99.99% uptime on our API, with a 99.9% SLA for all customers, described on our standard service level agreement. A premium SLA is offered to enterprise customers.
We sanitize data input to manage the risk of SQL injections.
We perform vulnerability scans monthly on the web application to detect application vulnerabilities. Secure development principles are included in our development lifecycle. Any vulnerability will go through triage to determine our risk exposure and determine the remediation priority.
We install patches that address security vulnerabilities on systems based on criticality. We strive to adhere to the following timelines:
CVSS that is 9 or greater: mitigate within 24 hours of discovery. Less than 30 days to implement a permanent fix
CVSS that is between 4 and 8.9: We strive to implement a permanent fix within 30 days
CVSS that is under 4: We strive to implement a permanent fix within 180 days
We have internally documented incident response procedures in place, which are tested at least once per calendar year. Customers are notified of any incident on our status page. If a given event impacts a specific user, they will be contacted by email.
There is a formal policy for risk management that outlines a defined risk assessment methodology. This has been approved by management and is reviewed and updated at least once per calendar year. We maintain a risk register which describes potential technical and business risks, estimates their change of occurrence, its potential business impact, and identifies any present and future mitigation actions to be taken.
LicenseSpring uses third parties for some activities to fulfill service requirements. We have a third-party risk management program in place to govern the selection, oversight, and risk assessment of third parties. The assessment is conducted prior to engaging their services, as well as on an ongoing basis as needed. An inventory of all third parties is not published for security and privacy reasons, but can be provided upon request on a case-by-case basis.