SOLUTIONS

INFORMATION
SECURITY AND
PRIVACY

Rival HR security

Keeping client data safe

Security is the foundation of our organization. Rival (formerly SilkRoad Technology) solutions have been built to keep your data safe. The Rival Executive Leadership Team and Board of Directors are committed to preserving the confidentiality, integrity and availability of client data.

Organizational Security

All Rival employees are required to complete security, privacy and compliance training during their onboarding experience and on an annual basis. We believe that information security is every employee’s responsibility in their day-to-day operations.

Infrastructure Security

Rival provides best-in-class protection through its hardware, software and operations management. The infrastructure layer is designed in a defense and depth approach to provide the highest levels of system confidentiality, integrity and availability.

Operational Security

Rival leverages industry-leading anti-malware solutions to ensure that any malicious behavior that attempts to penetrate the firewall, IPS and DMZ is caught at the server level and eradicated. Rival leverages security solutions to continuously monitor the performance and safety of its solutions and network to mitigate risks and prevent system delays or outages.

Rival HR - security

System Monitoring and Redundancy

SYSTEM MONITORING

Rival’s IT infrastructure is subject to annual penetration testing and scanned monthly for vulnerabilities using industry-leading technology. A portfolio of tools is used to alert responsible groups of component failures and thresholds indicating problems.

SYSTEM REDUNDANCY

Rival strives to eliminate any single point of failure by maintaining a highly available, secure environment that is ready for immediate failover. This is done through process flow among multiple devices and multiple service providers. This function is tested annually through our SOC 2 audit.

Rival HR - Security governance

Security governance, risk and compliance

Rival uses CIS Top 20, NIST and the ISO 27000 family of information security standards as the framework of our security practice.

These policies and practices are evaluated semi-annually through internal review and annually by an independent SOC 2 audit.

General Data Protection Regulation

Rival is a processor of foreign data and maintains all GDPR related standards and requirements for its clients.

Rival also meets the requirements defined by the Swiss-U.S. Data Privacy Framework, the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. Data Privacy Framework. These requirements are examined yearly.

Rival HR data protection
Rival HR - personal information protection

Personally Identifiable Information

Personally identifiable information (PII) is encrypted throughout Rival’s applications and infrastructure.

Data commonly accepted as sensitive and needing encryption would be social security numbers, drivers license numbers and bank account numbers, as well as other fields determined by the client.

onboarding training

UNDERREPRESENTED GROUPS

The American Institute of Certified Public Accountants has developed the SOC framework for safeguarding the confidentiality and privacy of information that is stored and processed in the cloud.

Data Privacy Framework (DPF)

The EU-U.S DPF., the UK Extension to the EU-U.S DPF. and Swiss-U.S. DPF allows companies on both sides of the Atlantic to comply with data protection requirements when transferring personal data between the EU and the U.S.

Rival clients can remain confident their data is protected, and the usability and availability of their data are preserved.

TALK TO AN EXPERT

Rival goes beyond traditional talent management to help our clients attract, retain, and align people to their business.