Institutional · Security
Wikimee Cybersecurity
Information security and data protection has always been our top priority and we have tirelessly pursued a robust and mature security strategy since the day the company was founded. Below is an overview of Wikimee's security strategy, which includes an incredible partnership with Amazon Web Services, to bring you the most comprehensive security in line with international standards.

Terms of Service
Agreements with a customer who opens an account or a user who joins an existing account.
read more →
Privacy
Our policy on what information we collect, how we use it and what choices you have.
read more →
Conduct when using
A list of acceptable and unacceptable conduct for our Services.
read more →Security features that bring more control, visibility and flexibility
If you have any security questions or concerns, please contact our sales team. They will provide you with additional security artifacts and external reports confirming our security maturity.

Identity and device management
Make sure that only the right people and approved devices can access your company information on Wikimee with features such as single sign-on, domain claiming and support for enterprise mobility management.

Data protection
By default, Wikimee encrypts data at rest and data in transit for all our customers. We further protect your data with tools such as Key Management, audit logs and integrations with leading data loss prevention (DLP) providers.

Information governance
Wikimee offers governance and risk management features flexible enough to meet your organization's needs, no matter what they are. This includes global retention policies, customized terms of service and support for eDiscovery.
Certifications and certificates of conformity
The AWS/Wikimee security program protects our organization and its data at every layer
ISO/IEC 27001
Information Security Management System (ISMS).
This independent, third-party certification ensures that Wikimee has an end-to-end security framework and a risk-based approach to managing information security. This certification illustrates Wikimee's dedication to establishing a best-practice security strategy in line with international security standards.
Download the certificate ↓ISO/IEC 27017
Security Controls for Provisioning and Using Cloud Services.
This certification guarantees that Amazon Web Services, as a cloud service provider and host of the Wikimee Platform, has a direct focus on the information security aspects of cloud computing and a system of strict controls specific to cloud services.
Download the certificate ↓ISO/IEC 27018
Protection of Personally Identifiable Information (PII).
This certification ensures that Wikimee, using AWS's sophisticated Information Protection tools, has measures in place to protect Personally Identifiable Information (PII) in accordance with the ISO/IEC 29100 privacy principles for the public cloud computing environment.
Download the certificate ↓ISO/IEC 27701
Privacy Information Management System (PIMS).
This certification ensures that Wikimee, as a PII Data Processor, maintains a robust privacy information management system to ensure that effective controls are in place, not only to meet the requirements of the GDPR (General Data Protection Regulation, the European data privacy law) and the CCPA (California Consumer Privacy Act), but also that best practices are used to meet the requirements of many other privacy legislations such as the LGPD (Brazilian Data Privacy Act).
Download the certificate ↓Our Security Policy
Data Protection Officer (DPO)
Name: Givaldo Marques da Silva
E-mail for LGPD matters: dpo@wikimee.com
Security · Our policy
Our security policy
Information Security Policy
Our Information Security Policy, the ISP, defines the internal security requirements and the industry security best practices applied to our work environment. As a requirement, all employees, collaborators, associates and service providers receive a copy and must sign it digitally.
To access our ISP, click here.
Application Security Process
The Application Security Process is a detailed Application Security Lifecycle process, fully integrated into the Wikimee Platform Software Development Lifecycle (SDLC), which includes:
- ISP, the Information Security Policy: internal security requirements defined through the signature and agreement of all employees, associates and service providers to our ISP, which defines the industry security best practices applied to our work environment.
- Continuous security review of architectures, design features and solutions.
- Interactive manual and automated source-code review (using static code analyzers) for security vulnerabilities and code quality, along with consulting and guidance for the development team.
- Regular manual assessment and dynamic scanning of the pre-production environment.
User authentication
Each Wikimee user has a unique, password-protected account with a verified email address. The password is validated against password policies and stored securely using a strong hashing algorithm with a unique formula (salt) for each password. Two-factor authentication is available as an additional security measure to protect Wikimee accounts.
Wikimee also supports several federated authentication methods for convenient and secure access to a Wikimee account by leveraging corporate credentials. Wikimee also offers advanced security settings that allow customers to manage the Network Access Policy and the Password Policy. More details can be found in our Help Center.
The Wikimee Support Team will be happy to help you with any issues related to the Services or the Platform itself. If troubleshooting or verifying a problem requires support to access your account, that access can be granted only by you and is enabled by a system-generated security token, which you provide to our support team, allowing access to solve your problem for a limited period of time. This systemic approach ensures additional confidentiality for your data stored on the Wikimee Platform.
Data sharing and role-based access control
A Wikimee account administrator manages and controls individual user rights, granting specific types of licenses such as administrator or a seat on the account.
Customer data, including demands, initiatives and workspaces, can only be accessed by other users within your Wikimee account if that information is specifically shared with them or if it is placed in shared workspaces.
Wikimee offers flexible data access control configuration, allowing administrators to set up Custom Access Roles, which offer a choice of many different permissions for user actions on the Wikimee Platform, and can be used to specify access levels for a user or a group to certain workspaces, initiatives and demands. Selective sharing can be enabled so as not to follow the default inheritance of sharing settings, giving more access control over specific initiatives, demands and profiles. Wikimee Access Reports allow administrators to comprehensively review user access to sensitive data.
Monitoring user activities
On enterprise accounts, Wikimee lets customers obtain a report with up-to-date information on account activity, including authentication events, changes to authorization and access controls, shared folders and tasks, and other security activities. The same report is available through a REST API that enables integration with Security Information and Event Management (SIEM) and Cloud Access Security Broker (CASB) systems.
Data encryption
Wikimee uses Transport Layer Security (TLS) 1.2 with a 256-bit AES algorithm in CBC mode and a 2,048-bit server key with leading modern browsers. When you access the Wikimee Platform via web browser, mobile apps, email or browser extension, TLS technology protects your information using server authentication and data encryption. This is equivalent to the network security methods used by banks and major e-commerce sites.
All passwords, cookies and sensitive user information are reliably protected against eavesdropping. User files uploaded to Wikimee servers through web applications and the API are automatically encrypted with 256-bit AES using per-file keys. If someone gained physical access to the file storage, that data would be encrypted and impossible to read directly. These encryption keys are stored in a secure key vault, which is a separate database decoupled from the file storage layer. In addition, all Wikimee workstations and servers are encrypted at rest using file-system encryption, where 256-bit AES is used.
Controlled access
We limit access to customer data to employees or collaborators who have a work-related need to access this data, and we require all such employees to sign a confidentiality agreement, the NDA (Non-Disclosure Agreement). Access to customer data is only performed as needed and only when approved by the customer (that is, as part of a support incident) through a support token, or under senior management authorization, or by security to provide support, maintenance or to improve service quality.
Processes
Designing and running the data center infrastructure requires not only technology but also a disciplined approach to processes. This includes policies on escalation, knowledge sharing, risk management and daily operations. The Wikimee security and operations teams have extensive experience designing and operating data centers, and we continuously improve our processes over time. Wikimee has also developed best-in-class practices for managing security and data protection risk. All of these elements are essential parts of our security culture.
Need to Know and Least Privilege
Only a limited set of employees has access to our data center and to the data stored in our databases. There are strict security policies for employee access. All security events are logged and monitored, and our authentication methods and data are strictly regulated. Production access requires establishing a VPN channel, multi-factor authentication, a one-time password and a personal certificate.
Try Wikimee with no strings attached
We set up a pilot project with your team, with a complete operating environment for testing and a consultation to boost your operations.
Try it for free