Laserfiche WebLink
Security and Hosting Overview <br />June 2015 <br />reasons, including testing of new or changed integration connectors, reports, <br />and/or application configuration changes such as revised approval <br />workflows. New application features can also be turned on and reviewed in <br />the sandbox before turning on in the live production instance. <br />• Any data deletion scripts that are developed between the customer and SAP <br />Fieldglass must be tested in a non -production environment prior to executing <br />in production. <br />• Customer Preview testing — this is an opportunity for customers to gain early <br />access to a future upgrade of the SAP Fieldglass application. This allows <br />customers to gain confidence that the system is working as expected prior to <br />the release date. Customer participation is optional. <br />• SAP Fieldglass regression testing — the SAP Fieldglass application is offered in <br />a Software as a Service (SaaS) model. One of the services we provide is testing <br />of the application prior to each production release. To ensure a customer's <br />configuration, integrations, and reports are working as expected with the <br />new codebase, SAP Fieldglass Quality Assurance uses a scrubbed production <br />copy of the database in our regression testing. Regression testing is where we <br />execute test cases against the current production codebase and the future <br />codebase using a common data input. Output files from each test are <br />compared to ensure any changes are expected. <br />Customers may opt out of this process. However, all responsibility in ensuring the <br />customer's SAP Fieldglass instance is properly working and maintained is transferred to <br />the customer. <br />To date, all SAP Fieldglass customers have declined to assume this responsibility. <br />1.6.5 Data Scrubbing <br />In order to properly service our customers, access to production data is required. All <br />customer data is classified as Confidential. SAP Fieldglass takes every possible precaution <br />to ensure data is protected from unauthorized access and misuse. <br />Data is protected in the following ways: <br />• First names and last names of buyers, suppliers, and workers are anonymized <br />by replacing with a test value. <br />• Email addresses of buyers, suppliers, and workers are changed to a single <br />false email address such as gatest8@SAP Fieldglass.com which is configured <br />to automatically purge all email sent to it. <br />• Buyer and supplier company names are anonymized. <br />• Any custom fields created by the customer remain unchanged. Custom fields <br />that contain sensitive data are encrypted with AES-256 and optionally display <br />masked when entering and displaying values in the user interface. There is no <br />way to decrypt these values since the decryption keys between production <br />and test are different. Keys are stored in the corporate password vault and <br />SAP Fieldglass P a g e 16 1 21 <br />