SOC2 type 2
Babelway has put in place an Information Security Management System (ISMS), which has been certified according to ISO27001 standard. Babelway’s policy regarding security can be consulted online at http://www.babelway.com/security-policy. The system ensures processes are in place to meet the policy’s objectives.
Babelway complies with the SOC2 Type 2 norm since 2013 and is yearly audited by KPMG (and formerly by Deloitte).
Below, please find the list of supported cipher suites:
- TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
- TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256
- TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
- TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA
- TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256
- TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384
- TLS_ECDH_RSA_WITH_AES_128_CBC_SHA
- TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256
- TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384
- TLS_RSA_WITH_AES_128_CBC_SHA
- TLS_RSA_WITH_AES_128_CBC_SHA256
- TLS_RSA_WITH_AES_256_CBC_SHA256
Babelway will also update the restrictions on algorithms applied to TLS handshaking and certification paths processing.
The following algorithms will be disabled for TLS handshaking:
- SSLv3
- TLSv1
- TLSv1.1
- RC4
- MD5withRSA
- DH with key size < 1024
- EC with key size < 224
- DES40 CBC
- RC4 40
The following algorithms must not be used during certification path processing.
- MD2
- MD5
- RSA with key size < 1024
- DSA with key size < 1024
- EC with key size < 224
It means that no signature algorithm involving MD2, MD5 will be used to verify a certificate. And the use of certificates with RSA/DSA key size less than 1024 bits in length or with EC key size less than 224 is restricted.
If you have any questions, please don’t hesitate to contact support@babelway.net