Protecting the confidentiality, integrity, and availability of customer information is one of Recognize’s highest priorities. This overview summarizes the security measures and practices we use to help protect customer data.
Looking for the latest security and compliance information?
Visit the Recognize Trust Center to review current certifications, security controls, policies, subprocessors, and available security documentation. Some resources may require an access request.
Secure your organization’s account
In addition to the protections maintained by Recognize, Company Admins can strengthen account security through authentication, user-management, privacy, and approval settings. Review our Recognize Security Best Practices.
Jump to a section
How Recognize Is Protected
Recognize uses an iterative approach to designing and improving its security procedures and controls. We continually evaluate the effectiveness of our security policies to help provide appropriate protection for our customers.
Data center security
Recognize servers are hosted in Amazon Web Services data centers. AWS data centers use electronic surveillance, multifactor access controls, and around-the-clock security personnel. Access is authorized according to least-privilege principles, and environmental systems are designed to minimize operational disruptions.
Secure connections
Connections to Recognize are secured using SSL/TLS. Attempts to connect over HTTP are redirected to HTTPS.
Application security
Recognize follows secure development practices that incorporate security reviews throughout application design, prototyping, development, and deployment.
Customer data protection
Customer data is classified as confidential and handled accordingly. Inbound and outbound logical firewalls help protect data from unauthorized access.
Intrusion detection and prevention
Recognize uses intrusion detection and intrusion prevention systems to identify anomalies at the infrastructure, network, and application levels.
Access and change monitoring
Access and change events are logged and monitored. Automated detection methods help identify suspicious access, activity, or system changes.
Hardened operating systems
Recognize runs on hardened Linux servers. Externally exposed critical patches are addressed within 24 hours.
Internal and third-party testing
Recognize routinely conducts internal and external vulnerability scans and penetration tests. Third-party security firms are also used for application testing.
Business continuity
Recognize customer data is backed up daily, encrypted at rest, and geographically distributed through AWS RDS. The backup retention period is seven days.
Authentication and Authorization
Access to Recognize is restricted to authorized users within a customer’s organization. Recognize provides features and integrations that help organizations manage users and control access to their data. Recognize browser extensions connect using OAuth.
User provisioning
Users can be provisioned through manual invitations, bulk invitations, OAuth 2.0 login, or User Sync. Depending on the organization’s configuration, user synchronization may be supported through services such as Microsoft 365, Yammer, or Active Directory using standard API or LDAP-based integrations.
Password policies
Recognize applies industry-standard password protections, including minimum password-length requirements. Passwords are protected using a salted, one-way 256-bit hashing process. Computational controls help mitigate brute-force password attacks.
OAuth 2.0 authentication
Access to Recognize may be granted through an OAuth 2.0 authentication flow. Supported options include Google and Microsoft services. Passwords are not transmitted to Recognize through OAuth 2.0. Following successful authentication, an API token is provided to make authorized requests on behalf of the authenticated user.
Single sign-on
Recognize supports SAML 2.0 single sign-on for eligible organizations. Additional configuration and security information is available in the Recognize SAML Security Document.
Personal Information
Depending on a customer’s configuration and the features being used, Recognize may store the following personal user information:
- First name, last name, and display name
- Email address
- Hire date, when provided for service anniversary recognition
- Birthday month and day, when provided for birthday recognition
- Phone number, when provided for SMS notifications
- Password credentials, unless third-party authentication or SSO is used
- IP address
- Job title
- Manager information
- Avatar or profile image
- Recognition messages, comments, approvals, and other information generated through the Recognize platform
Optional fields are collected only when customers choose to provide them or enable the related functionality.
Additional Privacy Information
Yammer feed data and Microsoft 365 data are not stored by Recognize through the applicable integrations. Aggregate information may be collected or analyzed to support application functionality and reporting.
For more information about how Recognize collects, uses, and protects personal information, review the Recognize Privacy Policy.
General Data Protection Regulation Compliance
Recognize supports compliance with applicable requirements of the European Union’s General Data Protection Regulation, or GDPR.
Users may request the removal of their personal data. Because recognition content can involve multiple people, certain recognition records may remain in the platform. However, identifying information associated with the requesting user, such as their name, email address, or display name, can be removed in response to an eligible request.
Note: Data requests are evaluated and processed in accordance with applicable law, contractual requirements, and Recognize policies.
Security and Compliance Resources
The Recognize Trust Center provides the most current information about our security and compliance program, including:
- ISO 27001:2022 certification documentation
- Security, privacy, and organizational controls
- Security and operational policies
- Penetration test attestations and related documentation
- Data categories and privacy controls
- Current subprocessors and service-provider information
Some Trust Center documents are available publicly, while others may require you to submit an access request.
For security-related questions, email security@recognizeapp.com. For product assistance, contact support@recognizeapp.com.
Technology References
- Microsoft Graph authentication
- Microsoft identity platform and OAuth 2.0
- Google OAuth 2.0 documentation
Security practices, platform features, integrations, and technical configurations may evolve. Refer to the Recognize Trust Center for the most current information.