Data Security
Validis uses advanced and proven methods of ensuring the utmost security of information. For example:
You control your data
The user's data is managed solely by the user in their own secure account. Validis keeps the data secure and backed up.
Data encryption
The Validis Connect software encrypts the data uploaded from the user's PC; it then transfers them to a secure web account that cannot be accessed by any user at any time, other than duly authorised owners. Consequently, it is protected and in a safe and secure environment at all times. About SSL Certificates
System separation
Validis does not interfere with the source accounting application. It is entirely non-intrusive. It works on a copy of the accounts, with no ability to affect the originals.
Host security
Validis services are hosted in a world class datacentre operated by Amazon. Validis shares the same physical facilities as the Amazon.com service. These datacentres provide a range of facilities that ensure the Validis Amatino service delivers the highest availability and dependability to our customers.
Certifications and Accreditations
Validis's hosting partner works with a public accounting firm to ensure continued Sarbanes Oxley (SOX) compliance and attain certifications such as recurring Statement on Auditing Standards No. 70: Service Organizations, Type II (SAS70 Type II) certification. These certifications provide outside affirmation that our hosting partner has established adequate internal controls and that those controls are operating efficiently.
Additionally, Validis has started work on certification under the equivalent European standard ISO27001. Validis and its parent, Future Route, operates internal processes in line with the guidelines of ISO27001 assessing risks and procedural controls for the security and integrity of its customers' data.
Security Testing
The Validis service is assessed through penetration testing by a trusted third party. All issues discovered through such testing are immediately actioned by our experienced systems engineering staff.
Physical Security
Protecting physical access to the Validis servers are extensive military-grade perimeter controls and protection. Physical access to the datacenter is strictly controlled both at the perimeter and at building access points by professional security staff utilising video surveillance, state of the art intrusion detection systems, and other electronic means. Authorized staff must pass two-factor authentication no fewer than three times to access data center floors. All visitors and contractors are required to present identification and are signed in and continually escorted by authorised staff. All access is logged and routinely audited.
Digital Security
Security of of Validis services are provided at multiple levels: The operating system (OS) of the host system, the virtual instance operating system, a stateful firewall and signed API calls. Each of these items builds on the capabilities of the others. The goal is to ensure that data contained within the Validis Amatino application cannot be intercepted by non-authorised systems or users and that Validis servers themselves are as secure as possible.
All adminstrator access to Validis servers is controlled using secure PKI access. All user access to the Validis service is performed over 256bit SSH web connections.
Validis services are protected against traditional network security issues such as:
- Distributed Denial Of Service (DDoS) Attacks
- Man In the Middle (MITM) Attacks
- IP Spoofing
- Port Scanning
All publicly facing servers are appropriately patched and secured.
Being a shared datacentre further measures are taken to ensure that other tenants have no access to Validis services. Packet sniffing is impossible due to physical measures taken by Amazon, and additionally, sensitive data is encrypted by the Validis Application.
Data Management
Validis services use secure storage within the datacentre with regular backups of customer data being taken. These backups are held on a rotational basis meaning customer data can be restored in the event of a service failure. All backup data is encrypted and is only accessible by system administrators with the appropriate security access. Backup data is stored in multiple redundant locations to protect against any physical device failure in a single location.
Redundancy
Validis services are operated in a fully redundant infrastructure meaning any single server failure will not interrupt operation of the service. Additionally, in the event of a complete datacentre failure, disaster recover processes enable Validis services to be restored in a second geographically diverse location in around 15 minutes.
Scalability
The Validis architecture operates on an industry standard technology platform and incorporates many design features to ensure scalability of the user interface and data processing tiers. Within the datacentre the Validis service can be scaled dynamically to accommodate exceptional load of the service. New servers can be brought on line automatically in the event of load spikes.
Staff and offices
Validis's secure offices and network are protected by comprehensive systems that control entry and access. Staff can only view uploaded data to address technical issues, and even then only with the user's permission.
Using Validis on third-party data
If you are a professional advisor, accountant or auditor, you should ensure you have the approval of your client before using Validis to work on their data. Validis Amatino is highly secure, and stringent data privacy rules are in place. You can see these terms in our privacy policy. In addition, two sample documents are available, one in Word and one as a PDF, which can be used as a template as part of the client engagement.
Validis makes no representation or warranty about advice, consulting or any specific outcome of the issues that might be found in the accounting data as a result of the Validis service being used.
If you have any issue or question then please feel free to Validis Support team.
Get started now
Validis is a secure Internet-based application that requires no additional software installation or hardware set up. Just subscribe and go or request a free demonstration.









