Strong, like Fort Knox

Strong and Safe

Well to start, ‘facilities’ is plural! Your relevance engines are hosted in multiple, geographically diverse facilities to ensure they are always available. We have mitigated risks by utilizing multiple communication technologies, geographic separation, provider diversification and communication provider diversification across our global facilities. We know you are depending on us when it matters most so we have built out state of the art facilities, as you would expect.

SAS70 type II certified

SAS 70 is a widely recognized and highly stringent auditing standard for service organizations developed by the American Institute of Certified Public Accountants (AICPA). Type II SAS 70 audits are comprised of an in-depth assessment and rigorous testing of a company’s control objectives, controls placed in operation, and operating effectiveness. The scope of the Type II audit includes controls over information technology and related processes, and it requires a service auditor to independently test the controls of an organization over an extended period of time. Our facilities have been audited by Ernst & Young and/or KPMG and have received SAS70 Type II certification.

Application resiliency

The platforms are multi-tiered applications ensuring that the platform will provide even if a component is not available. Additionally components and layers of the application are geographically disbursed so our capabilities are always available. xMatters uses its proven service provider deployment architecture to ensure the highest level of reliability, including:

  • Clustered application tiers (presentation, business, communication, and data)
  • Tiers scale by adding servers/resources – adding and removing servers can be done on-line to minimize customer impact
  • Voice infrastructure: using both TDM and VOIP technologies, dynamically scalable based on system or geographic needs

Network resiliency

To ensure availability we have contracted with multiple providers of network services for both data and voice services. We use servers that are specified with scalability and reliability in mind, eliminating single points of failure wherever possible. All servers have dual power supplies and, where applicable, redundant network connectivity. Additional measures include:

  • Concrete vaults for fiber entry
  • Self-healing network – automatic failover to redundant paths
  • Network neutral; connects to all major carriers and located near major Internet hubs
  • High bandwidth capacity

Power

At a minimum we utilize N+1 redundancy on all critical power, cooling and network systems. Power is provided by dual municipal power feeds entering the buildings at different points. Highlights include:

  • Underground utility power feed
  • Redundant (N+1) UPS systems
  • Redundant (N+1/2N) power distribution units (PDUs)
  • Redundant (N+1) diesel generators with on-site diesel fuel storage

Datacenters

Our data centers are also located geographically far apart from each other, eliminating the possibility of a “regional” disaster crippling the service. The closest two sites are over 900 miles away! Our centers are high availability datacenters.

  • Slab-on-grade (concrete) floor with raised floor
  • Early-warning VESDA fire detection system (very early smoke detection apparatus)
  • Both smoke and high temperature detectors
  • Power, HVAC, security, fire, and leak detection systems
  • Dual authentication at every entry to the datacenter floor

Network monitoring and protection

In order to ensure the highest possible security and performance, all layers of our service are monitored by the xMatters client assurance and operations teams. We perform continuous monitoring including processing of synthetic transactions to ensure performance as well as health. Additional highlights include:

  • Perimeter firewalls and edge routers block unused protocols
  • Internal firewalls segregate traffic between the application and database tiers
  • Intrusion detection sensors throughout the internal network report events to a security event management system for logging, alerts, and reports

Backups

All data are backed up to backup appliance and sent off-site to a secured backup location using an encrypted link. Once archives are retired they are securely destroyed.

Disaster recovery

We perform real-time replication to disk at each data center, and near real-time data replication between the production data center and the disaster recovery center. We only transmit data across encrypted link and periodically verify our projected recovery times and the integrity of the customer data.