Picsart Products Security, Privacy, and Architecture Information Security Datasheet

(effective as of October 2022; subject to change without notice)

Policy Ownership

Picsart has a documented information security policy that all employees must read and acknowledge. This policy is reviewed and updated annually. Security policy development, maintenance, and issuance is the responsibility of the Picsart Information Security Team.

Picsart Infrastructure

For UShosted customers, Picsart hosts the Picsart Services with Amazon Web Services in their USEast1 region, Virginia, USA. Some Picsart Services may also be hosted on Google Cloud in their East US region.
 
For Europehosted customers, Picsart hosts the Picsart Services with Amazon Web Services in their EUCentral1 region, Frankfurt area, Germany, with some S3 storage containers in EUWest1 in Ireland.

Third-Party Architecture

Picsart may use one or more thirdparty content delivery networks to provide the Picsart Services and to optimize content delivery via the Picsart Services. Content items to be served to subscribers or endusers, such as images or attachments uploaded to the Picsart Services, may be cached with such content delivery networks to expedite transmission.
 
Information transmitted across a content delivery network may be accessed by that content delivery network solely to enable these functions.

Security Controls

1. Organization Security
Picsart’s CTO is responsible for the overall security of the Picsart Services, including oversight and accountability. Picsart’s contracts with thirdparty hosting providers such as Amazon Web Services and Google Cloud Platform include industrystandard information protection requirements.

2. Asset Classification and Logical Access Control
Picsart maintains an inventory of essential information assets such as servers, databases, and information. All Customer Data is classified as “Secret” by Picsart.
 
Picsart adopts the principle of least privilege for all accounts running application or database services, as well as with its own staff. For example, User Success Managers only have access to the regions for which they are directly responsible. Picsart maintains separate development, staging (or sandbox), user acceptance testing, and production environments access to each environment and within each environment is strictly controlled.
 
Access to Picsart’s servers are controlled via revocable SSH keys managed via configuration management and rotated at least annually. All access to Picsart’s servers or Customer Data is logged and can only be accessed through Picsart’s VPN. Database access is controlled via 32 and 64character passwords with IP whitelisting. Picsart’s HR onboarding and offboarding processes handle provisioning and deprovisioning of accounts and access.
 
3. Personnel Security
All employees at Picsart sign a nondisclosure agreement when their employment begins. In addition, Picsart conducts background checks of its employees as part of its onboarding process. All employees are informed of, and agree to comply with, Picsart’s security policies and practices as a part of their initial onboarding.
System administrators, developers and other users with privileged access receive special and ongoing training and are subjected to additional background screening.

4. Physical and Environmental Security
Access to Picsart facilities is controlled by 24hour security. Additionally, all Picsart offices are protected by locked
access and are under 24hour video surveillance. All Picsart employee workstations are encrypted and password
protected, and all Picsart user accounts require twofactor authentication.
 
Data centers and servers are managed and controlled by our Cloud hosting providers, GCP and Amazon Web Services.
 
Details regarding the security practices & controls applicable to these facilities can be found at
their websites:
AWS: https://aws.amazon.com/security/
Google Cloud Platform: https://cloud.google.com/architecture/framework/securityprivacycompliance

5. Policies and Logging
The Picsart Services are operated in accordance with the following procedures to enhance security:
User passwords are never transmitted or stored in clear text
Picsart uses industrystandard methods to determine password validity
API key information for thirdparty services provided by the customer are encrypted for storage
Picsart keeps audit logs for all access to production servers
Server access is controlled via public key access, instead of passwords, and only permitted while on VPN
Logs are stored in a secure centralized host to prevent tampering
Picsart application and ssh audit logs are stored for one year
Passwords are not logged under any circumstances
Access to Picsart mail and document services is only allowed on approved mobile devices that have automated
security policies enforced, such as encryption, autolock and passwords
All access to customer dashboard accounts by Picsart Employees must be done through an internal service that is
accessible via VPN only
As part of Picsart’s Employee Information Security Policy, employees may not store any Customer Data on
removable media

6. Intrusion Detection
Picsart monitors system, user, and file behavior across its infrastructure using a hostbased Intrusion Detection System. Intrusion Detection alerts are monitored by the Security and Ops monitoring teams 24/7. Additionally, Picsart may analyze data collected by users’ web browsers (e.g., device type, screen resolution, time zone, operating system version, browser type and version, system fonts, installed browser plugins, enabled MIME types, etc.) for
security purposes, including to detect compromised browsers, to prevent fraudulent authentications, and to ensure
that the Picsart Services function properly.
 
Picsart’s APIs and Dashboard use strict rolebased access controls and user permissioning. Unauthorized web requests and API calls are logged and automatically alert Picsart’s engineering team.

7. Security Logs
All Picsart systems used in the provision of the Picsart Services, including firewalls, routers, network switches, and
operating systems log information to their respective system log facility or a centralized syslog server (for network
systems) in order to enable security reviews and analysis. Picsart has automated alerts and searches on these logs.

8. Vulnerability Management
Picsart’s infrastructure and applications are regularly scanned based on Vulnerability Management Policy. Reports are analysed by our Security Team and addressed at least monthly. Picsart also maintains a list membership to various CVE vulnerability mailing lists. Patches and ‘critical’ and ‘high’ vulnerabilities are remediated no later than 30 days following discovery.
 
Picsart runs VDP (Vulnerability Disclosure Program) with HackerOne, which creates clear guidelines for researchers
and ethical hackers to submit security vulnerabilities to Picsart while also helping us mitigate risk by supporting and
enabling the disclosure and remediation of vulnerabilities before they are exploited
 
Picsart also uses static code analysis tools during the build process (such as GitHub repositories dependabot and
MobSF framework) to perform static security analysis.
 
9. ThirdParty Penetration Testing
Picsart undergoes a thirdparty penetration test of the Picsart Services on an annual basis.

10. Monitoring
For technical monitoring, maintenance and support processes, Picsart uses a combination of tools to ensure that
processes and servers are running properly, including but not limited to:
Process monitoring
CPU, disk, and memory monitoring
Uptime monitoring
Functional monitoring
Database monitoring
APM performance monitoring
Error monitoring

11. Customer Access Control
The Picsart Services employ a variety of security controls. These include, but are not limited to:
API IP Whitelisting Defines the range of IP addresses from which a customer’s users can access the
Picsart API to prevent unauthorized third parties from accessing the Picsart Services.
Dashboard Account IP Whitelisting Defines a range of IP addresses from which a customer’s users can
access the Picsart Dashboard to prevent unauthorized parties from accessing the Picsart Services.
Singlesign on with a Google Account Picsart customers can access the Picsart Services by means of a
Google Account, which allows customers to configure such access to require twofactor authentication.
Singlesign on via Okta Picsart customers can access the Picsart Services via Okta, which allows
customers to configure access via their Okta installation.
Mobile Authenticator Picsart customers can enable two factor authentication via Authy which allows a
mobile authenticator to be required for access to the Picsart Dashboard.
CustomerConfigurable Roles and Permissions Picsart customers have the option to manage their users of
the Picsart Services through selective and granular permissioning.
All requests on the Picsart Dashboard have crosssite request forgery (CSRF) protection. All web services
use encrypted HTTPS for all traffic and disallow all HTTP traffic via HTTP Strict Transport Security
(“HSTS”).
Picsart does not use cookies for session storage to avoid replay attacks. Sessions expire after a few hours
of inactivity.
User passwords on the Picsart Dashboard must meet minimum password length requirements. At the
customer’s request, Picsart can add password complexity requirements, such as lowercase, uppercase,
numeral, and special characters, and set a password expiration policy such that users must change their
passwords regularly.
User password history of the last six passwords prevents the reuse of User passwords.
Failed login attempts are recorded and an account is locked out with the owner notified after multiple
failed attempts.
Picsart’s REST APIs are accessed with separate API keys, which can only be provisioned by Picsart
dashboard user accounts with administrative access. API keys are granted access to specific API
endpoints when created.

12. Development and Maintenance
Picsart uses tools such as GitLab and Jenkins to effectively manage the development lifecycle. During testing,
Picsart generates sandbox accounts and fake data for testing. Picsart does not use production data in sandbox
accounts.
 
Application source control is accomplished through private GitHub repositories. Picsart has controls in place to ensure that all code must be approved before being merged to Picsart’s main code branch; only the CTO and approved employees are granted access to promote code to production.
 
Picsart developers receive additional security training as part of their onboarding, and undergo regular and periodic security training during the term of their employment. Picsart maintains a list of core security principles for engineering and highlevel guidelines on security topics for secure software development.
 
13. Malware Prevention
As a mitigating factor against malware, all Picsart servers run LTS editions of Operation Systems, as well as endpoint monitoring and antivirus services.
 
Picsart adopts the principle of least privilege for all accounts running application or database services. Proper change management ensures that only authorized packages are installed via a package management system containing only
trusted software, and that software is never installed manually.
 
All Picsart employee computers have virus scanners installed and updated definitions sent out from a central device management platform.

14. Information Security Incident Management
Picsart maintains written and regularlyaudited security incident management policies and procedures, including an Incident Response Plan to be enacted in the event of an incident.

Picsart has 24x7x365 oncall incident management staff.

15. Data Encryption
The Picsart Services use industryaccepted encryption practices to protect Customer Data and communications during transmissions between a customer’s network and the Picsart Services, including 256bit TLS Certificates and 2048bit RSA public keys at a minimum.
 
Picsart audits the TLS ciphers used in connection with the provision of the Services with thirdparty security auditors to ensure that anonymous or weak ciphers are not used. These audits also confirm that the Services do not allow client renegotiation, support downgrade attack protection and forward secrecy.
 
Data shipped to Amazon Web Services is encrypted in transit and atrest using AES256 encryption via Amazon’s
managed encryption key process. Data shipped to databases is encrypted atrest using AES256 encryption via Luks encryption process.

Where use of the Services requires a customer to provide access to third party services (for example, AWS S3 credentials for data exports), Picsart performs additional encryption of that information.

16. Return and Deletion of Customer Data
The Picsart Services allow import, export, and deletion of Customer Data by authorized users at all times during the term of a customer’s subscription. Following termination or expiration of the Services, Picsart shall securely overwrite or delete Customer Data within 60 days following any such termination, in accordance with the Agreement, applicable laws and the Documentation.

17. Reliability and Backup
All networking components, SSL accelerators, load balancers, Web servers and application servers are configured in a redundant configuration. All Customer Data submitted to the Picsart Services is stored on a primary database server with multiple active clusters for higher availability. All database servers replicate in near realtime and are backed up on a regular basis. Backups are encrypted using AES256 encryption and verified for integrity.

18. Business Continuity Management and Disaster Recovery
Picsart has a written Business Continuity and Disaster Recovery Plan, which is tested annually. Picsart tests database backups and failovers as part of our Business Continuity Plan. Backups are encrypted and stored in Amazon Web Services.
 
19. Mobile Device Management Policies
Picsart uses Mobile Device Management (“MDM”) platforms to control and secure access to Picsart resources on mobile devices such as phones, tablets, and laptops. Picsart uses Google for its phone and tablet MDM policy, and enforces common security settings such as, but not limited to, encryption, lock screen passwords, password expiration, display timeouts, and remote location and remote wipe. Picsart uses Cisco Meraki for laptop and desktop management to enforce common security settings, including but not limited to, hard disk encryption, security patches, and remote location and remote wipe capabilities.
 
20. Blocking Third Party Access
The Picsart Services have not been designed to include any backdoors or similar functionality that would allow the
government or any third parties to access Customer Data. We do not voluntarily provide any government or other third party with encryption keys, or any other way to break our encryption.

21. Payment processing
Picsart is outsourcing it’s payment processing to thirdparty payment processors which are PCI DSS (Payment Card Industry Data Security Standard) compliant.

22. How does Picsart isolate customer data?
All data stored by Picsart on behalf of customers has strong tenant isolation security and control capabilities.
 
Picsart Services utilize Amazon S3 which provides advanced data access controls.
 
23. Contacts
Picsart’s Security Team can be reached by emailing [email protected].