ABM Tech

Security

Cyber security and information security are two of ABM Tech's four practice areas, which means the people setting our internal controls are the same specialists we place with clients. Our teams work with Rapid7 and Tenable for threat detection, Fortra, Checkmarx and SonarQube for vulnerability management, and Qualys, Tripwire and LogRhythm across monitoring and SIEM.

Security is a service line here, not a policy page

Because our engineers work inside client systems, the risk we manage is not abstract. Network and endpoint controls run through Fortinet, Sophos, Trend Micro, McAfee and Barracuda; application security testing through Burp Suite, Acunetix and Invicti. The same specialists who set these controls internally are the ones we place with clients.

AICPA
SOC
AICPA
Type 2

How We Handle Your Data

Secure Personnel

ABM Tech takes the security of its data and that of its customers seriously and ensures that only vetted personnel are given access to their resources.

  • All ABM Tech contractors and employees undergo background checks prior to being engaged or employed by us in accordance with local laws and industry best practices.
  • Confidentiality or other types of Non-Disclosure Agreements (NDAs) are signed by all employees, contractors, and others who have a need to access sensitive or internal information.
  • We embed the culture of security into our business by conducting employee security training & testing, using current and emerging techniques and attack vectors.

Secure Development

ABM Tech follows industry-standard programming techniques for development documentation and quality assurance processes to ensure that our customer applications meet modern security standards.

  • All development projects at ABM Tech, LLC, including on-premises software products, support services, and our own Digital Identity Cloud offerings, follow secure development lifecycle principles.
  • All development of new products, tools, and services, as well as major changes to existing ones, undergoes a design review to ensure security requirements are incorporated into proposed development.
  • All team members who are regularly involved in any system development undergo annual secure-development training in coding or scripting languages that they work with, as well as any other relevant training.
  • Software development is conducted in line with OWASP Top 10 recommendations for web application security.

Secure Testing

ABM Tech deploys third-party penetration testing and vulnerability scanning of all production and internet-facing systems on a regular basis.

  • All new systems and services are scanned prior to being deployed to production.
  • We perform penetration testing on new systems or major changes to existing systems to ensure a comprehensive and real-world view of our environment.
  • We perform static and dynamic software application security testing of all code, including open-source libraries, as part of our software development process when signed by our customers.

Secure Cloud Infrastructure

ABM Tech builds on modern, hardened cloud infrastructure providers — AWS, GCP, and Azure — and applies the same defense-in-depth controls across every environment.

  • Production systems run in private VPCs with strict inbound/outbound rules and network segmentation between tiers.
  • All traffic is encrypted in transit with TLS 1.2+; data is encrypted at rest with provider-managed KMS keys.
  • Centralized logging, monitoring, and alerting with 24/7 on-call rotations on mission-critical workloads.
  • Infrastructure is managed as code (Terraform / CloudFormation) with peer review and automated drift detection.

Data Handling & Privacy

ABM Tech treats customer data with the same care as our own. Access is least-privilege by default, audited, and bounded to the scope of the engagement.

  • Role-based access control with periodic access reviews; just-in-time elevation for any sensitive operation.
  • Data classification policy identifies regulated data (PII, PHI, financial) and applies stricter controls end-to-end.
  • Data retention and secure deletion procedures align with customer contracts and applicable regulations.
  • Subprocessor list maintained and shared on request; incident-notification SLAs defined in every MSA.

Build with a partner who takes your data seriously

Have a question about our security-first posture, subprocessors, or a specific control? We'll answer on the first call.

Start a Project