{"id":985,"date":"2022-04-05T22:09:04","date_gmt":"2022-04-05T22:09:04","guid":{"rendered":"https:\/\/marketing-dot-excom-staging.uc.r.appspot.com\/?page_id=985"},"modified":"2024-05-20T11:56:24","modified_gmt":"2024-05-20T15:56:24","slug":"security","status":"publish","type":"page","link":"https:\/\/staging.cms.exercise.com\/security\/","title":{"rendered":"Security"},"content":{"rendered":"<p>We are fully HIPAA compliant and our payments infrastructure is PCI Level 1 compliant\u2014your clients payment, package, and other data are safeguarded with enterprise-grade security.<\/p>\n<h2>Hosting &amp; Deployment<\/h2>\n<p>Exercise.com is hosted as an application in Google Cloud Platform (GCP) in the USA, Canada, the EU, the United Kingdom, and Australia. We also utilize Amazon Web Services (AWS) to serve some assets. These Google and Amazon facilities hold all major security and data privacy accreditations, including SOC1 \u2013 SSAE-16, SOC2, PCI DSS Level 1, ISO 27001, HIPAA, and FIPS 140-2.<\/p>\n<p>The physical access to servers in the data centers are restricted to authorized Google and Amazon personnel. Exercise.com employees have no physical access to the servers. We don&#8217;t host any on-premise infrastructure and we require two-factor authentication for all employees that work with internal systems (code repositories, build systems, cloud providers, etc.). We apply the \u201cleast privilege\u201d model meaning we assign access to employees based on the absolute least access someone needs to be able to perform their duties.<\/p>\n<p>Exercise.com engages a 3rd-party cybersecurity company to conduct regular penetration tests, no less than annually, and to evaluate and prescribe accordance with all HIPAA compliance standards and industry security best practices.<\/p>\n<h2>Storage &amp; Encryption<\/h2>\n<p>All customer data is always encrypted, in transit and at rest. We use an up to date TLS 1.x protocol for all control communications, including data transfer between components, to ensure all traffic is encrypted. For data at rest, we use AES 256-bit, one of the most secure encryption protocols.<\/p>\n<h2>Backup &amp; Resiliency<\/h2>\n<p>Exercise.com services are deployed using industry best practices. High availability and disaster recovery is built-in into our cloud architecture. In case of a component failure, the platform launches additional instances and redirects the load.<\/p>\n<p>Exercise.com&#8217;s backup policies and procedures outline the critical resources, including the databases, that are backed-up automatically to enable recovery needed to meet our SLAs. All production data is being replicated automatically to a separate infrastructure. Exercise.com backs up its data continuously.<\/p>\n<h2>Sub-Processors<\/h2>\n<p>We limit the extent of data sharing with our sub-processors to the degree that is minimally necessary to provide our service and make sure that all the technology providers that we use:<\/p>\n<ul class=\"dashed small\">\n<li>Pass regular security reviews and audits;<\/li>\n<li>Comply with data protection and privacy regulations (SOC 2 and\/or ISO 27001);<\/li>\n<li>Have good reputation (publicly listed or private companies with reputable backers).<\/li>\n<\/ul>\n<p>We encrypt (see Encryption &amp; Access Control) all customer data stored in our infrastructure providers&#8217; (GCP and AWS) data centers in transit and at rest. We share only limited information with Stripe, necessary to manage subscriptions, invoice and process payments (including customers&#8217; billing addresses, contact details and bank account details). We use customer relations management software, HubSpot, Salesforce, and Salesloft, to automate the communication with customers and to store customer contacts in their systems.<\/p>\n<table class=\"ranking bench\" style=\"height: 164px;\" width=\"838\">\n<thead>\n<tr>\n<th>Sub-Processor<\/th>\n<th>Description<\/th>\n<th>HQ Location<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Alphabet Inc.<\/td>\n<td>Google Cloud Platform (GCP) offered by Google is a cloud computing service. GCP is compliant with SOC 1\/2\/3, ISO\/IEC 27001, PCI DSS and other major security regulations. We use GCP to host its application, as well as to store the backup data using encrypted geo-redundant cloud storage.<\/td>\n<td>Mountain View, CA<\/td>\n<\/tr>\n<tr>\n<td>Amazon.com, Inc.<\/td>\n<td>Amazon Web Services (AWS) is a subsidiary of Amazon providing an on-demand cloud computing service. AWS is compliant with SOC 1\/2\/3, ISO\/IEC 27001, PCI DSS and other major security regulations. We use Amazon Web Service to host certain assets in our application, and store the backup data using encrypted geo-redundant cloud storage.<\/td>\n<td>Seattle, WA<\/td>\n<\/tr>\n<tr>\n<td>Stripe, Inc.<\/td>\n<td>Stripe offers payment processing and anti-fraud tools which we use to accept payments from customers, manage subscriptions, and perform transaction reporting. Stripe is certified as a PCI Level 1 Service Provider, which is the most stringent level of certification available in the payments industry.<\/td>\n<td>San Francisco, CA<\/td>\n<\/tr>\n<tr>\n<td>HubSpot, Inc.<\/td>\n<td>HubSpot provides tools for customer relationship management (CRM), social media marketing, <a href=\"https:\/\/www.exercise.com\/grow\/lead-generation-strategies-for-gyms\/\" data-lasso-id=\"2\">lead generation<\/a> and web analytics. It has TRUSTe certification for Enterprise Privacy and its IT is audited as part of the Sarbanes Oxley compliance. We use HubSpot CRM and analytics tools to manage and automate our sales processes.<\/td>\n<td>Cambridge, MA<\/td>\n<\/tr>\n<tr>\n<td>Salesforce, Inc.<\/td>\n<td>Salesforce, Inc. is an American cloud-based software company headquartered in San Francisco, California. It provides customer relationship management software and applications focused on sales, customer service, marketing automation, analytics, and application development.<\/td>\n<td>San Francisco, CA<\/td>\n<\/tr>\n<tr>\n<td>Salesloft<\/td>\n<td>Salesloft is a sales engagement platform. The company was founded in September 2011. Though its original product offering focused on sales development, the company has since expanded its platform to offer functionality for the entire sales organization.<\/td>\n<td>Atlanta, GA<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Compliance<\/h2>\n<p>Exercise.com complies with all major industry regulations and is HIPAA and GDPR compliant. For customers that process Protected Health Information (PHI) and Personally Identifiable Information (PII) we will sign a Business Associate Agreement (please visit here for the <a href=\"https:\/\/www.exercise.com\/security\/baa\/\" data-lasso-id=\"3\">HIPAA Business Associate Agreement<\/a>). The General Data Protection Regulation (GDPR) regulates data protection in the European Union (EU) and the European Economic Area (EEA). Exercise.com is compliant with GDPR. We have a Data Protection Officer who can be reached by <a href=\"https:\/\/www.exercise.com\/company\/contact\/\" data-lasso-id=\"4\">contacting us<\/a>.<\/p>\n<h2>Transparency Report<\/h2>\n<p>As of December 15, 2022, Exercise.com has not received any law enforcement or government information requests. Exercise.com has not built backdoors for any government into our services.<\/p>\n<p>The following summary covers 2022 calendar year through 12-15-2022:<\/p>\n<table class=\"transparency ranking bench\">\n<thead>\n<tr>\n<th>Category of Request<\/th>\n<th>Total Requests<\/th>\n<th>Challenged, No Data Disclosed<\/th>\n<th>Completed, Data Disclosed<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td colspan=\"8\"><b>U.S. Requests<\/b><\/td>\n<\/tr>\n<tr>\n<td>Court Orders<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<\/tr>\n<tr>\n<td>National Security Requests<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<\/tr>\n<tr>\n<td>Search Warrants<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<\/tr>\n<tr>\n<td>Subpoenas<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<\/tr>\n<tr>\n<td colspan=\"8\"><b>Non-U.S. Requests<\/b><\/td>\n<\/tr>\n<tr>\n<td>All Non-U.S. Countries<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Additional Information<\/h2>\n<p>For more information, please visit the following pages:<\/p>\n<ul>\n<li><a href=\"\/terms\/cookie-policy\/\" data-lasso-id=\"5\">Cookie Policy<\/a><\/li>\n<li><a href=\"\/company\/privacy\/\" data-lasso-id=\"6\">Privacy Policy<\/a><\/li>\n<li><a href=\"\/terms\/\" data-lasso-id=\"7\">Terms of Service<\/a><\/li>\n<li><a href=\"https:\/\/www.exercise.com\/security\/baa\/\" data-lasso-id=\"8\">HIPAA Business Associate Agreement (BAA)<\/a><\/li>\n<li><a href=\"\/security\/ccpa\/\" data-lasso-id=\"9\">California Privacy Rights<\/a><\/li>\n<li><a href=\"\/terms\/data-protection\/\" data-lasso-id=\"10\">Data Protection Policy<\/a><\/li>\n<li><a href=\"\/terms\/data-processing\/\" data-lasso-id=\"11\">Data Processing Agreement<\/a><\/li>\n<li><a href=\"\/terms\/data-retention\/\" data-lasso-id=\"12\">Data Retention Policy &amp; Schedule<\/a><\/li>\n<li><a href=\"\/company\/advertiser-disclosure\/\" data-lasso-id=\"13\">Advertiser Disclosure<\/a><\/li>\n<li><a href=\"\/company\/editorial-guidelines\/\" data-lasso-id=\"14\">Editorial Guidelines<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>We are fully HIPAA compliant and our payments infrastructure is PCI Level 1 compliant\u2014your clients payment, package, and other data are safeguarded with enterprise-grade security. Hosting &amp; Deployment Exercise.com is hosted as an application in Google Cloud Platform (GCP) in the USA, Canada, the EU, the United Kingdom, and Australia. We also utilize Amazon Web [&hellip;]<\/p>\n","protected":false},"author":8,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-985","page","type-page","status-publish","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.7.9 - aioseo.com -->\n\t<meta name=\"description\" content=\"We undergo independent verification of our security, privacy, and compliance controls to help you meet your regulatory and policy objectives.\" \/>\n\t<meta name=\"robots\" content=\"noindex, nofollow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/staging.cms.exercise.com\/security\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.7.9\" \/>\n\n\t\t<meta name=\"fo-verify\" content=\"37a28663-3081-49c0-b10a-0c03e95954b6\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Exercise.com | Software to grow your fitness business\" \/>\n\t\t<meta property=\"og:type\" content=\"website\" \/>\n\t\t<meta property=\"og:title\" content=\"Security, Privacy, &amp; Compliance | Exercise.com\" \/>\n\t\t<meta property=\"og:description\" content=\"We undergo independent verification of our security, privacy, and compliance controls to help you meet your regulatory and policy objectives.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/staging.cms.exercise.com\/security\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/staging.cms.exercise.com\/wp-content\/uploads\/2022\/05\/default-image.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/staging.cms.exercise.com\/wp-content\/uploads\/2022\/05\/default-image.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@exercise\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Security, Privacy, &amp; Compliance | Exercise.com\" \/>\n\t\t<meta name=\"twitter:description\" content=\"We undergo independent verification of our security, privacy, and compliance controls to help you meet your regulatory and policy objectives.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/staging.cms.exercise.com\/wp-content\/uploads\/2022\/05\/default-image.png\" \/>\n\t\t<meta name=\"google\" content=\"nositelinkssearchbox\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/security\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/staging.cms.exercise.com\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/security\\\/#listItem\",\"name\":\"Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/security\\\/#listItem\",\"position\":2,\"name\":\"Security\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/#organization\",\"name\":\"Exercise.com LLC\",\"description\":\"Software to grow your fitness business\",\"url\":\"https:\\\/\\\/staging.cms.exercise.com\\\/\",\"email\":\"sales@exercise.com\",\"telephone\":\"+18889904041\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/staging.cms.exercise.com\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/ColorPrism-TextDark-h.svg\",\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/security\\\/#organizationLogo\",\"width\":312,\"height\":94,\"caption\":\"Exercise.com Logo\"},\"image\":{\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/security\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.instagram.com\\\/exercisecom\\\/\",\"https:\\\/\\\/www.tiktok.com\\\/@exercisecom\",\"https:\\\/\\\/www.pinterest.com\\\/exercisecom\\\/\",\"https:\\\/\\\/www.youtube.com\\\/@exercise\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/exercisecom\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/security\\\/#webpage\",\"url\":\"https:\\\/\\\/staging.cms.exercise.com\\\/security\\\/\",\"name\":\"Security, Privacy, & Compliance | Exercise.com\",\"description\":\"We undergo independent verification of our security, privacy, and compliance controls to help you meet your regulatory and policy objectives.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/security\\\/#breadcrumblist\"},\"datePublished\":\"2022-04-05T22:09:04-04:00\",\"dateModified\":\"2024-05-20T11:56:24-04:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/#website\",\"url\":\"https:\\\/\\\/staging.cms.exercise.com\\\/\",\"name\":\"Exercise.com\",\"description\":\"Software to grow your fitness business\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/staging.cms.exercise.com\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Security, Privacy, &amp; Compliance | Exercise.com<\/title>\n\n","aioseo_head_json":{"title":"Security, Privacy, & Compliance | Exercise.com","description":"We undergo independent verification of our security, privacy, and compliance controls to help you meet your regulatory and policy objectives.","canonical_url":"https:\/\/staging.cms.exercise.com\/security\/","robots":"noindex, nofollow, max-snippet:-1, max-image-preview:large, max-video-preview:-1","keywords":"","webmasterTools":{"miscellaneous":"&lt;meta name=\"fo-verify\" content=\"37a28663-3081-49c0-b10a-0c03e95954b6\" \/&gt;"},"og:locale":"en_US","og:site_name":"Exercise.com | Software to grow your fitness business","og:type":"website","og:title":"Security, Privacy, &amp; Compliance | Exercise.com","og:description":"We undergo independent verification of our security, privacy, and compliance controls to help you meet your regulatory and policy objectives.","og:url":"https:\/\/staging.cms.exercise.com\/security\/","og:image":"https:\/\/staging.cms.exercise.com\/wp-content\/uploads\/2022\/05\/default-image.png","og:image:secure_url":"https:\/\/staging.cms.exercise.com\/wp-content\/uploads\/2022\/05\/default-image.png","og:image:width":1200,"og:image:height":628,"twitter:card":"summary_large_image","twitter:site":"@exercise","twitter:title":"Security, Privacy, &amp; Compliance | Exercise.com","twitter:description":"We undergo independent verification of our security, privacy, and compliance controls to help you meet your regulatory and policy objectives.","twitter:image":"https:\/\/staging.cms.exercise.com\/wp-content\/uploads\/2022\/05\/default-image.png","schema":""},"aioseo_meta_data":{"post_id":"985","title":"Security, Privacy, &amp; Compliance #separator_sa #site_title","description":"We undergo independent verification of our security, privacy, and compliance controls to help you meet your regulatory and policy objectives.","keywords":[],"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":{"id":"aioseo-web-page-636cf6fd91fe8","slug":"web-page","graphName":"WebPage","label":"Web Page","properties":{"type":"WebPage","name":"","description":""}}},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":{"title":{"suggestions":[],"usage":0},"description":{"suggestions":[],"usage":0}},"created":"2022-04-07 07:54:55","updated":"2024-05-20 15:56:25"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/staging.cms.exercise.com\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u203a<\/span><span class=\"aioseo-breadcrumb\">\n\tSecurity\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/staging.cms.exercise.com"},{"label":"Security","link":"https:\/\/staging.cms.exercise.com\/security\/"}],"_links":{"self":[{"href":"https:\/\/staging.cms.exercise.com\/wp-json\/wp\/v2\/pages\/985","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/staging.cms.exercise.com\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/staging.cms.exercise.com\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/staging.cms.exercise.com\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.cms.exercise.com\/wp-json\/wp\/v2\/comments?post=985"}],"version-history":[{"count":7,"href":"https:\/\/staging.cms.exercise.com\/wp-json\/wp\/v2\/pages\/985\/revisions"}],"predecessor-version":[{"id":892105,"href":"https:\/\/staging.cms.exercise.com\/wp-json\/wp\/v2\/pages\/985\/revisions\/892105"}],"wp:attachment":[{"href":"https:\/\/staging.cms.exercise.com\/wp-json\/wp\/v2\/media?parent=985"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}