Privileged access at Cloud de Confiance by S3NS

Cloud de Confiance by S3NS systems are built with a focus on protecting your content using controls and monitoring. Your content stored on Cloud de Confiance by S3NS completely belongs to you. Occasionally, S3NS personnel might need to access your content but these accesses are never without a valid business justification.

Why S3NS personnel request access to Customer Data

The most common reason why S3NS personnel request access to Customer Data is to resolve a customer support ticket. If you create a customer support request, then a S3NS personnel might be required to request access to your data. Access Transparency exists to provide customers visibility into these accesses.

What is privileged access

S3NS personnel's access to your data to fulfill an obligation of providing a contracted service is called privileged access. Access to your data in Cloud de Confiance by S3NS is usually because of the following reasons:

  • You are accessing your own data.
  • A service you are using is accessing data on your behalf.

When requested to provide a contracted service, S3NS personnel acting as a privileged administrator can access your data.

Foundational principles of privileged access management

Cloud de Confiance by S3NS's privileged access management strategy strictly limits what a single S3NS staff member can view and do with your data. Cloud de Confiance by S3NS's privileged access philosophy is based on the following principles:

  • Least privilege: Access to Customer Data is denied by default for all S3NS personnel. When access is granted, it is temporary and no greater than what is absolutely necessary to provide the contracted service.

  • Limit singular access to data: Singularly accessing Customer Data without another individual involved is extremely difficult for any and every S3NS personnel.

  • All access must be justified: By default, S3NS personnel don't have access to Customer Data. S3NS personnel can access your data only with an active, valid business justification. S3NS personnel can't access Customer Data for justifications that are closed or where the S3NS person is not a directly linked collaborator. For the list of valid business justifications, see Justification reason codes.

  • Monitor and alerting: Monitoring and response processes exist to identify, triage, and remediate violations of these principles.

What's next

  • To see the list of business justifications for which S3NS personnel can request to access customer data, see Justification reason codes.