CurrentWare Cloud is our fully hosted, managed version of the CurrentWare Suite. This article explains how CurrentWare Cloud protects your data at the infrastructure, platform, and client level, and how it supports your organization's compliance requirements.
For the on-premises/BYO-cloud security model (self-hosted SQL Server, local client-server architecture), see CurrentWare Security & Assurance Practices. This article covers the CurrentWare Cloud (SaaS) deployment specifically.
Infrastructure & Hosting
- Hosted on AWS: CurrentWare Cloud runs on Amazon Web Services (AWS) managed services under a shared responsibility model. AWS secures the physical data centers and underlying infrastructure; CurrentWare secures configuration, identity and access management, encryption settings, monitoring, and incident response.
- Company location: CurrentWare Inc. is headquartered in Toronto, Ontario, Canada.
- Data residency: Data is processed and stored in AWS US-East-2 (Ohio). EU, UK, and Australian data residency options may be available for eligible customers; check with your CurrentWare representative for regional hosting availability.
Client-Side Security
- Encrypted transmission: Activity data collected by the CurrentWare Client is transmitted to CurrentWare Cloud over encrypted connections (TLS/HTTPS). The Cloud Client uses the same underlying client architecture as the on-premises product: data is held in an encrypted local database on the endpoint before being sent to CurrentWare's servers, then cleared from local storage once received.
- Unstoppable by design: End-users cannot stop, pause, or uninstall the Client without administrator credentials, ensuring monitoring and policy enforcement continue uninterrupted.
- Stealth Mode: The Client can be deployed in stealth mode so it does not appear in the end-user's visible programs list.
- Password protected: If the Client is made visible to end-users, it remains protected by an admin password to prevent tampering.
- Role-Based Access Control (RBAC): Administrators create password-protected Operator accounts with access limited to specific functions, user groups, or PC groups. Operators only see the data and controls relevant to their role.
- Two-Factor Authentication (2FA): Admins and Operators can be required to authenticate with a username/password plus a time-based one-time password (TOTP).
- Single Sign-On (SSO): CurrentWare Cloud supports authentication through your organization's existing identity provider, reducing password fatigue and phishing risk.
- Admin audit logs: Every configuration change, policy update, and login to the web console is logged, answering "who did what, where, and when."
Data Security & Retention
- Encryption in transit and at rest: Data is encrypted in transit using industry-standard protocols (TLS) and encrypted at rest using AWS-managed encryption capabilities.
- Configurable retention: Customers control how long activity data and screenshots are retained. Data can be configured to auto-delete on a set schedule or once a storage threshold is reached. By default CurrentWare will house 6 months of data with your cloud subscription.
- Selective data collection: Organizations can choose what is tracked, disable specific tracking categories, or limit monitoring to set hours or days.
- Post-termination deletion: Upon contract termination, customers can elect to have their securely deleted. Deletion from active systems completes within 90 days of the request; backup copies are purged in the normal backup rotation cycle.
- Screenshot storage: Captured screenshots for CurrentWare Cloud deployments are stored in CurrentWare-managed Amazon S3 storage (within the same AWS environment as the rest of the Service), not on customer-designated infrastructure.
Security Assessments & Compliance Alignment
- Third-party security assessment: An independent security vendor has assessed CurrentWare's practices for confidentiality, availability, and integrity of its IT assets and data.
- Penetration testing: CurrentWare engages a cybersecurity firm to perform internal and external penetration testing aligned with the OWASP Top 10 and MITRE ATT&CK frameworks, with findings reviewed and remediated.
- Security framework alignment: CurrentWare's information security policy and controls are aligned to the ISO 27001/27002 standard, with additional practices drawn from NIST 800-171, the NIST Cybersecurity Framework (CSF), and the CyberSecure Canada Baseline Controls.
- Supports customer compliance programs: CurrentWare's monitoring, access control, and logging features are designed to help your organization meet the technical controls required by frameworks such as ISO 27001, NIST 800-171, CMMC, HIPAA, GDPR, and CIPA. CurrentWare's own information security program is aligned to these standards.
- Data Processing Addendum (DPA): CurrentWare's DPA sets out our obligations as a data processor, including breach notification within 72 hours of discovery, subprocessor management, and international transfer mechanisms (including EU/UK Standard Contractual Clauses where applicable). See the Data Processing Addendum for full details.
Frequently Asked Questions
Where is my CurrentWare Cloud data hosted?
CurrentWare Cloud is hosted on Amazon Web Services (AWS).
Can CurrentWare access my organization's monitoring data?
Access is limited to authorized CurrentWare personnel on a need-to-know basis for support and platform operations, governed by our Data Processing Addendum.
How long is my data retained?
You control retention through the console, including automatic deletion schedules. The default retention period is 6 months; but can be increased based on your needs. Contact your CurrentWare representative to discuss your data retention needs.
Is CurrentWare Cloud GDPR/HIPAA/ISO 27001 compliant?
CurrentWare's security program is aligned with ISO 27001/27002, NIST, and other frameworks, and our DPA is built to support GDPR, PIPEDA, CCPA, and similar laws. CurrentWare provides the technical controls and contractual framework to help your organization meet these requirements; your organization remains responsible for its own compliance program and lawful basis for processing.
What happens to my data if I cancel my subscription?
You can request your data be securely deleted. Deletion from active systems is completed within 90 days of your request. Data will be purged automatically based on our DPA at the appropriate time in other cases.
Related Articles