This question has been flagged
2 Replies
4802 Views

How can I be sure that all my valuable business data is safe when using the OE SaaS offer?

  • What measures are taken to secure the business data?
  • Are there independent parties who review/audit data security?
  • How is contingency / backup / data recovery organized?
  • Who is responsible in case of data loss?
  • Is there a SLA?
  • Is the actual performance versus SLA reported?
  • Are there penalties when the system is down?

Is there any documentation on this subject?

Avatar
Discard
Best Answer
  • What measures are taken to secure the business data?
    There are basically 2 sorts of security: at the infrastructure level (physical and whatever is below the application stack), and at the application level. For the first one, OpenERP uses OVH as host in Europe (I see you are in The Netherlands) and the security is whatever they put in place. Considering it is the largest European host, you can expect a pretty solid service on that side. For the second one, all transactions are encrypted (check the certificate on the SaaS).
  • Are there independent parties who review/audit data security?
    The whole community reviews the code on a constant basis.
  • How is contingency / backup / data recovery organized?
    OpenERP Online includes a service of incremental backups: 1h ago, 2h, 3h, 12h, 24h, 5days, 15d, 30d,...
  • Who is responsible in case of data loss?
    The most data loss there can be is 1 hour of work (see incremental backups), and I don't think it has ever happened on the SaaS.
  • Is there a SLA?
    OpenERP Online includes OpenERP Enterprise. It comes with an SLA specifying a maximum time to open an issue ticket. OVH also guarantees 99.99% of uptime which corresponds to 60 seconds of max downtime per week.
  • Is the actual performance versus SLA reported?
    No
  • Are there penalties when the system is down?
    It's on a case by case basis.
Avatar
Discard
Best Answer

You should contact OpenERP for this information (phone numbers for your region at the bottom of the contact page) - they don't regularly monitor these community help pages.

Avatar
Discard