Advanced Cloud Security and Compliance that Protects Enterprise Systems and Data

Move to Tier 3's cloud with confidence

Cloud Security & Compliance that Exceeds Your Requirements

With Tier 3’s “defense in depth" approach, customer environments are protected by multiple security measures at every level – securing physical equipment, cloud resources, and customer data. In addition, an extensive permissions system extending to the group and individual VM levels ensure only authorized users can access and alter systems. And we’ve worked with the leading IT auditing firms to ensure our systems are ready to support most global organizations.

Account Security

Tier 3 provides customers with role-based access to their cloud environments through authentication and authorization permissions set explicitly per resource type. Users access the Control Portal with a username and password, or by Single Sign On through SAML. All actions performed by users through the Control Portal — such as provisioning servers, adding public IP addresses and powering-on a server — are logged and auditable. These logs are never deleted, and customers can view access logs on an entity by entity basis.

Network Security

Tier 3 establishes a robust digital perimeter around your cloud environment. All environments reside within private networks created or extended by an Active Directory Domain. Access to customer servers can only be done via a certificate-based VPN connection unless specific public ports have been explicitly opened up by the customer. Customers can extend to two-factor authentication via LDAP (Microsoft Active Directory or OpenLDAP on Linux) for additional security where needed.

Customer environments on Tier 3 are protected by a series of redundant Juniper SRX firewalls employing Unified Thread Management (UTM) technology. Each customer service runs on its own private VLAN, and each virtual machine is isolated with zone-based firewalls. Customers can also use secure connections such as Persistent\User VPN, Direct Connection, or MPLS.

Datacenter Intrusion Detection System (IDS) and Intrusion Detection and Protection System (IDP) attack detection and prevention features screen incoming traffic for potential attacks. This protection is available data center-wide, and is implicitly enabled. In unique cases, customers may request deep content inspection policies and enable IPSEC at the OS level to encrypt all network traffic. We also provide customers with Microsoft Forefront for additional identity and access protection. Read this KB article for more details on Tier 3 and IDS & IDP.

In addition to real-time monitoring and NOC support, we perform Nessus vulnerability scans upon request. Then, we work with the customer to remediate any identified vulnerabilities. To make sure that cloud servers are regularly protected with the latest operating system patches, Tier 3 offers customers an auto-patch service that keeps customer machines up-to-date with vendor updates.

Physical Security

Each Tier 3 data center is housed within private, caged enclosures. Entry to the data center premises requires an electronic proximity key card. Data center facilities are staffed 24x7x365 and monitored by cameras. An electronic proximity card control portal, biometric scan, and onsite data center personnel provide additional security inside the facility. Only Tier 3 authorized staff are allowed access to the private cage enclosure and they access physical hosts via two factor VPN authentication (SSH or RDP Access with Local administrator/root account and password required). All access is logged in both the control panel and the ticketing system.

Tier 3 Security &
Compliance at a Glance


Physical Security
  • Physical security controls audited to SSAE 16 or ISO 27001 standards
  • All access is logged in both the control panel and the ticketing system.
Logical
  • Logical security policies and processes audited to SSAE 16 standards – built around IT best practices
  • Server and Operating System hardening
  • Managed carrier class firewalls
  • Intrusion Prevention services included
  • DDOS mitigation services included
  • Dedicated VLANs/IP addresses
  • Transparent database encryption available
  • Nessus vulnerability scanning included
  • Managed anti-virus
  • 24x7 monitoring and incident management
Account
  • Role-based access - authentication and authorization permissions set explicitly per resource type
  • Username/password or SAML sign on
  • All actions logged and auditable
Audits
  • SSAE 16
  • Support for complex regulations like HIPAA

Watch a Video

The Complete Enterprise Cloud in action. View this 7-minute product demo, and learn more about Tier 3's cloud infrastructure, cloud management, and platform as a service capabilities.

Tier 3 Considered "Visionary"

Tier 3 has been positioned by Gartner, Inc. as a Visionary in the 2012 Magic Quadrant for Public Cloud Infrastructure as a Service.

Get the Report

Customer Success Stories

We’ve helped businesses like yours be more successful in the cloud.



View Success Stories

Get a Quote

Ready to talk pricing? Tell us about your project, and let our cloud experts put a proposal together for you.


Request a Quote