Picsart Products Security, Privacy, and Architecture Information Security Datasheet
(effective as of October 2022; subject to change without notice)
Policy Ownership
Picsart has a documented information security policy that all employees must read and acknowledge. This policy is reviewed and updated annually. Security policy development, maintenance, and issuance is the responsibility of the Picsart Information Security Team.
Picsart Infrastructure
For US–hosted customers, Picsart hosts the Picsart Services with Amazon Web Services in their US–East–1 region, Virginia, USA. Some Picsart Services may also be hosted on Google Cloud in their East US region.
For Europe–hosted customers, Picsart hosts the Picsart Services with Amazon Web Services in their EU–Central–1 region, Frankfurt area, Germany, with some S3 storage containers in EU–West–1 in Ireland.
Third-Party Architecture
Picsart may use one or more third–party content delivery networks to provide the Picsart Services and to optimize content delivery via the Picsart Services. Content items to be served to subscribers or end–users, such as images or attachments uploaded to the Picsart Services, may be cached with such content delivery networks to expedite transmission.
Information transmitted across a content delivery network may be accessed by that content delivery network solely to enable these functions.
Security Controls
1. Organization Security
Picsart’s CTO is responsible for the overall security of the Picsart Services, including oversight and accountability. Picsart’s contracts with third–party hosting providers such as Amazon Web Services and Google Cloud Platform include industry–standard information protection requirements.
Picsart’s CTO is responsible for the overall security of the Picsart Services, including oversight and accountability. Picsart’s contracts with third–party hosting providers such as Amazon Web Services and Google Cloud Platform include industry–standard information protection requirements.
2. Asset Classification and Logical Access Control
Picsart maintains an inventory of essential information assets such as servers, databases, and information. All Customer Data is classified as “Secret” by Picsart.
Picsart adopts the principle of least privilege for all accounts running application or database services, as well as with its own staff. For example, User Success Managers only have access to the regions for which they are directly responsible. Picsart maintains separate development, staging (or sandbox), user acceptance testing, and production environments access to each environment and within each environment is strictly controlled.
Access to Picsart’s servers are controlled via revocable SSH keys managed via configuration management and rotated at least annually. All access to Picsart’s servers or Customer Data is logged and can only be accessed through Picsart’s VPN. Database access is controlled via 32 and 64–character passwords with IP whitelisting. Picsart’s HR onboarding and off–boarding processes handle provisioning and de–provisioning of accounts and access.
3. Personnel Security
All employees at Picsart sign a non–disclosure agreement when their employment begins. In addition, Picsart conducts background checks of its employees as part of its onboarding process. All employees are informed of, and agree to comply with, Picsart’s security policies and practices as a part of their initial onboarding.
System administrators, developers and other users with privileged access receive special and ongoing training and are subjected to additional background screening.
All employees at Picsart sign a non–disclosure agreement when their employment begins. In addition, Picsart conducts background checks of its employees as part of its onboarding process. All employees are informed of, and agree to comply with, Picsart’s security policies and practices as a part of their initial onboarding.
System administrators, developers and other users with privileged access receive special and ongoing training and are subjected to additional background screening.
4. Physical and Environmental Security
Access to Picsart facilities is controlled by 24–hour security. Additionally, all Picsart offices are protected by locked
access and are under 24–hour video surveillance. All Picsart employee workstations are encrypted and password
protected, and all Picsart user accounts require two–factor authentication.
Data centers and servers are managed and controlled by our Cloud hosting providers, GCP and Amazon Web Services.
Details regarding the security practices & controls applicable to these facilities can be found at
their websites:
their websites:
AWS: https://aws.amazon.com/security/
Google Cloud Platform: https://cloud.google.com/architecture/framework/security–privacy–compliance
Google Cloud Platform: https://cloud.google.com/architecture/framework/security–privacy–compliance
5. Policies and Logging
The Picsart Services are operated in accordance with the following procedures to enhance security:
● User passwords are never transmitted or stored in clear text
● Picsart uses industry–standard methods to determine password validity
● API key information for third–party services provided by the customer are encrypted for storage
● Picsart keeps audit logs for all access to production servers
● Server access is controlled via public key access, instead of passwords, and only permitted while on VPN
● Logs are stored in a secure centralized host to prevent tampering
● Picsart application and ssh audit logs are stored for one year
● Passwords are not logged under any circumstances
● Access to Picsart mail and document services is only allowed on approved mobile devices that have automated
security policies enforced, such as encryption, autolock and passwords
● All access to customer dashboard accounts by Picsart Employees must be done through an internal service that is
accessible via VPN only
● As part of Picsart’s Employee Information Security Policy, employees may not store any Customer Data on
removable media
6. Intrusion Detection
Picsart monitors system, user, and file behavior across its infrastructure using a host–based Intrusion Detection System. Intrusion Detection alerts are monitored by the Security and Ops monitoring teams 24/7. Additionally, Picsart may analyze data collected by users’ web browsers (e.g., device type, screen resolution, time zone, operating system version, browser type and version, system fonts, installed browser plug–ins, enabled MIME types, etc.) for
security purposes, including to detect compromised browsers, to prevent fraudulent authentications, and to ensure
that the Picsart Services function properly.
Picsart’s APIs and Dashboard use strict role–based access controls and user permissioning. Unauthorized web requests and API calls are logged and automatically alert Picsart’s engineering team.
7. Security Logs
All Picsart systems used in the provision of the Picsart Services, including firewalls, routers, network switches, and
operating systems log information to their respective system log facility or a centralized syslog server (for network
systems) in order to enable security reviews and analysis. Picsart has automated alerts and searches on these logs.
8. Vulnerability Management
Picsart’s infrastructure and applications are regularly scanned based on Vulnerability Management Policy. Reports are analysed by our Security Team and addressed at least monthly. Picsart also maintains a list membership to various CVE vulnerability mailing lists. Patches and ‘critical’ and ‘high’ vulnerabilities are remediated no later than 30 days following discovery.
Picsart runs VDP (Vulnerability Disclosure Program) with HackerOne, which creates clear guidelines for researchers
and ethical hackers to submit security vulnerabilities to Picsart while also helping us mitigate risk by supporting and
enabling the disclosure and remediation of vulnerabilities before they are exploited
and ethical hackers to submit security vulnerabilities to Picsart while also helping us mitigate risk by supporting and
enabling the disclosure and remediation of vulnerabilities before they are exploited
Picsart also uses static code analysis tools during the build process (such as GitHub repositories dependabot and
MobSF framework) to perform static security analysis.
MobSF framework) to perform static security analysis.
9. Third–Party Penetration Testing
Picsart undergoes a third–party penetration test of the Picsart Services on an annual basis.
Picsart undergoes a third–party penetration test of the Picsart Services on an annual basis.
10. Monitoring
For technical monitoring, maintenance and support processes, Picsart uses a combination of tools to ensure that
processes and servers are running properly, including but not limited to:
● Process monitoring
● CPU, disk, and memory monitoring
● Uptime monitoring
● Functional monitoring
● Database monitoring
● APM performance monitoring
● Error monitoring
11. Customer Access Control
The Picsart Services employ a variety of security controls. These include, but are not limited to:
● API IP Whitelisting – Defines the range of IP addresses from which a customer’s users can access the
Picsart API to prevent unauthorized third parties from accessing the Picsart Services.
● Dashboard Account IP Whitelisting – Defines a range of IP addresses from which a customer’s users can
access the Picsart Dashboard to prevent unauthorized parties from accessing the Picsart Services.
● Single–sign on with a Google Account – Picsart customers can access the Picsart Services by means of a
Google Account, which allows customers to configure such access to require two–factor authentication.
● Single–sign on via Okta – Picsart customers can access the Picsart Services via Okta, which allows
customers to configure access via their Okta installation.
● Mobile Authenticator – Picsart customers can enable two factor authentication via Authy which allows a
mobile authenticator to be required for access to the Picsart Dashboard.
● Customer–Configurable Roles and Permissions – Picsart customers have the option to manage their users of
the Picsart Services through selective and granular permissioning.
● All requests on the Picsart Dashboard have cross–site request forgery (CSRF) protection. All web services
use encrypted HTTPS for all traffic and disallow all HTTP traffic via HTTP Strict Transport Security
(“HSTS”).
● Picsart does not use cookies for session storage to avoid replay attacks. Sessions expire after a few hours
of inactivity.
● User passwords on the Picsart Dashboard must meet minimum password length requirements. At the
customer’s request, Picsart can add password complexity requirements, such as lowercase, uppercase,
numeral, and special characters, and set a password expiration policy such that users must change their
passwords regularly.
● User password history of the last six passwords prevents the reuse of User passwords.
● Failed login attempts are recorded and an account is locked out with the owner notified after multiple
failed attempts.
● Picsart’s REST APIs are accessed with separate API keys, which can only be provisioned by Picsart
dashboard user accounts with administrative access. API keys are granted access to specific API
endpoints when created.
12. Development and Maintenance
Picsart uses tools such as GitLab and Jenkins to effectively manage the development lifecycle. During testing,
Picsart generates sandbox accounts and fake data for testing. Picsart does not use production data in sandbox
accounts.
Application source control is accomplished through private GitHub repositories. Picsart has controls in place to ensure that all code must be approved before being merged to Picsart’s main code branch; only the CTO and approved employees are granted access to promote code to production.
Picsart developers receive additional security training as part of their onboarding, and undergo regular and periodic security training during the term of their employment. Picsart maintains a list of core security principles for engineering and high–level guidelines on security topics for secure software development.
13. Malware Prevention
As a mitigating factor against malware, all Picsart servers run LTS editions of Operation Systems, as well as endpoint monitoring and antivirus services.
As a mitigating factor against malware, all Picsart servers run LTS editions of Operation Systems, as well as endpoint monitoring and antivirus services.
Picsart adopts the principle of least privilege for all accounts running application or database services. Proper change management ensures that only authorized packages are installed via a package management system containing only
trusted software, and that software is never installed manually.
trusted software, and that software is never installed manually.
All Picsart employee computers have virus scanners installed and updated definitions sent out from a central device management platform.
14. Information Security Incident Management
Picsart maintains written and regularly–audited security incident management policies and procedures, including an Incident Response Plan to be enacted in the event of an incident.
Picsart has 24x7x365 on–call incident management staff.
15. Data Encryption
The Picsart Services use industry–accepted encryption practices to protect Customer Data and communications during transmissions between a customer’s network and the Picsart Services, including 256–bit TLS Certificates and 2048–bit RSA public keys at a minimum.
Picsart audits the TLS ciphers used in connection with the provision of the Services with third–party security auditors to ensure that anonymous or weak ciphers are not used. These audits also confirm that the Services do not allow client renegotiation, support downgrade attack protection and forward secrecy.
Data shipped to Amazon Web Services is encrypted in transit and at–rest using AES–256 encryption via Amazon’s
managed encryption key process. Data shipped to databases is encrypted at–rest using AES–256 encryption via Luks encryption process.
managed encryption key process. Data shipped to databases is encrypted at–rest using AES–256 encryption via Luks encryption process.
Where use of the Services requires a customer to provide access to third party services (for example, AWS S3 credentials for data exports), Picsart performs additional encryption of that information.
16. Return and Deletion of Customer Data
The Picsart Services allow import, export, and deletion of Customer Data by authorized users at all times during the term of a customer’s subscription. Following termination or expiration of the Services, Picsart shall securely overwrite or delete Customer Data within 60 days following any such termination, in accordance with the Agreement, applicable laws and the Documentation.
17. Reliability and Backup
All networking components, SSL accelerators, load balancers, Web servers and application servers are configured in a redundant configuration. All Customer Data submitted to the Picsart Services is stored on a primary database server with multiple active clusters for higher availability. All database servers replicate in near real–time and are backed up on a regular basis. Backups are encrypted using AES–256 encryption and verified for integrity.
18. Business Continuity Management and Disaster Recovery
Picsart has a written Business Continuity and Disaster Recovery Plan, which is tested annually. Picsart tests database backups and failovers as part of our Business Continuity Plan. Backups are encrypted and stored in Amazon Web Services.
19. Mobile Device Management Policies
Picsart uses Mobile Device Management (“MDM”) platforms to control and secure access to Picsart resources on mobile devices such as phones, tablets, and laptops. Picsart uses Google for its phone and tablet MDM policy, and enforces common security settings such as, but not limited to, encryption, lock screen passwords, password expiration, display timeouts, and remote location and remote wipe. Picsart uses Cisco Meraki for laptop and desktop management to enforce common security settings, including but not limited to, hard disk encryption, security patches, and remote location and remote wipe capabilities.
Picsart uses Mobile Device Management (“MDM”) platforms to control and secure access to Picsart resources on mobile devices such as phones, tablets, and laptops. Picsart uses Google for its phone and tablet MDM policy, and enforces common security settings such as, but not limited to, encryption, lock screen passwords, password expiration, display timeouts, and remote location and remote wipe. Picsart uses Cisco Meraki for laptop and desktop management to enforce common security settings, including but not limited to, hard disk encryption, security patches, and remote location and remote wipe capabilities.
20. Blocking Third Party Access
The Picsart Services have not been designed to include any backdoors or similar functionality that would allow the
government or any third parties to access Customer Data. We do not voluntarily provide any government or other third party with encryption keys, or any other way to break our encryption.
The Picsart Services have not been designed to include any backdoors or similar functionality that would allow the
government or any third parties to access Customer Data. We do not voluntarily provide any government or other third party with encryption keys, or any other way to break our encryption.
21. Payment processing
Picsart is outsourcing it’s payment processing to third–party payment processors which are PCI DSS (Payment Card Industry Data Security Standard) compliant.
22. How does Picsart isolate customer data?
All data stored by Picsart on behalf of customers has strong tenant isolation security and control capabilities.
Picsart Services utilize Amazon S3 which provides advanced data access controls.