Chris (Veracode, Inc.) asked a question.

How is my intellectual property protected when I upload it (binaries and source where appropriate)?

  • Darren_Me (Community Member)

    Application uploads (binary or source) are stored and transmitted encrypted, using currently-recognized best practices. They are temporarily decrypted only in memory, and only when necessary; they are never stored in the clear.

     

    Uploads are made using TLS, and our TLS configuration is routinely tested to ensure it gets an A+ rating. The uploaded application is then encrypted with a unique AES256 key managed by a commercial key management system.

     

    Our scanning servers temporarily decrypt the binary in memory while it is analyzed, and discard the decrypted binary and local-memory copy of the key the moment they're no longer needed for analysis.

     

    At the end of the customer-defined retention period, the encrypted data is deleted from our systems. The AES key that was used to protect it is then destroyed, preventing access even if the encrypted data were recovered.

    Expand Post

Topics (0)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.