Rapid delivers foundational enterprise-grade security critical for your APIs. Rapid’s approach to security and trust focuses on business continuity access control, data privacy, and disaster recovery encapsulated in an Information Security Management System that meets national and international data security and privacy standards.
Encryption
Rapid enforces all communication with the API Hub for Enterprise using TLS 1.2 to the highest level of encryption supported by your client. At rest, your data is encrypted using AWS KMS, which has been independently validated and certified, including in the AWS SOC reports, PCI DSS, and FedRAMP approvals.
Data Location
API Hub for Enterprise can deliver the service from across several geographical locations, including the United States, Canada, and the European Union.
Privacy
Rapid is subject to similar privacy requirements as our customers. Our privacy program is inclusive with our security program and has been deployed to meet the data privacy requirements of many regulations globally.
Business Continuity
Rapid replicates real-time production data and stores data in geographically separated redundant data centers. Each data center location has a security control framework in place that is equivalent to our production data centers.
Our Information Security Management System (ISMS) is a risk-based ISMS and based on numerous international standards and the regulatory frameworks. We have implemented approximately 230 unique controls across Rapid that are applicable to the API Hub for Enterprise SaaS service, the technology stack and endpoint systems we use for business operations. The control framework includes but is not limited to the following key control families.
Rapid controls access to information and information processing facilities and systems by implementing controls relating to:
To ensure that security is built into everything that we do, we have deployed the following operational processes:
As both a Data Controller, Processor and Sub-Processor, Rapid ensures the operational processes and legal mechanisms we have in place are appropriate to meet the privacy obligations placed on us as either a Data Controller or Processor. An example of some of the processes we have in place are:
To ensure information security is an integral part of the design lifecycle and all changes are appropriately managed, Rapid controls the following:
To ensure the sub-processing and processing services that we leverage meets or exceeds our security and data privacy obligations, we tightly manage the:
Ensuring service availability is a critical responsibility for Rapid.
Rapid's API Hub for Enterprise gives organizations comprehensive governance and security capabilities for API publishing and consumption across all APIs in the organization, including role-based access control (RBAC) and federated identity.
UPTIME
SLA
GLOBAL
Tech support
GDPR
Compliance
ISO 27001
Certificate
WEBINAR
This talk examines issues around data security regulations and APIs and provides recommendations for ensuring API and data privacy and security.
BLOG
This article hopes to center your understanding of API governance by providing the benefits, essential definitions, and best practices.
GUIDE
With the rise of APIs, API security demands more focus than ever. We manage privacy, access control, and attack prevention for APIs in API security. Let's discuss some practices that can help secure REST APIs.
Ready to experience the power of Rapid?
Contact Rapid to get started.