Jive Software aggregates data from our public cloud customer instances. The kinds of data we collect include usage statistics, user travel patterns, adoption statistics, and other anonymous information. Among other things, this information helps us to make decisions about future product development and improvement. In addition, your contract sets forth how we protect your user-generated content (i.e., we access this data solely to provide support and other services to you as you request).
Every form throughout the application is protected from CSRF by a token scoped to each request which prevents forgery attempts. The server requires the token on any request that can change data. If the token is not present or does not match, the HTTP request will fail.
Yes. All web services are tested as part of an automated monthly security scan process.
There are a number of known security issues with Internet Explorer (IE). In particular, IE will attempt to display or execute a file even if the web server sends an HTTP header indicating that the browser should download, instead of display, the file. This behavior, also known as "content sniffing" or "MIME sniffing," allows attackers to upload seemingly okay files (for example, an MS Word file) that actually contain malicious HTML. An IE user would then attempt to view the file. If the file is not zipped, IE will "sniff" the contents of the file, determine that the file is HTML, and then attempt to render the HTML instead of opening the file with MS Word.
The following types of files are zipped by Jive when they are attached to content: text/plain and text/HTML. Jive uses a magic number process to determine the correct MIME type of an uploaded file. For example, if a document called mydocument.doc is uploaded, the magic number process will validate the document. If the file is actually an HTML file, then Jive zips the file as a security precaution.
Yes. Jive uses Sun's JVM 1.6 and the Java Secure Socket Extension (JSSE), which is FIPS 140-compliant.
Jive uses Sun's JVM 1.6 and the Java Secure Socket Extension (JSSE).
Jive supports X.509-based PKI. However, extra configuration steps are required; we recommend a Jive Professional Services customization.
Yes. We can encrypt your dedicated databases that reside in our hosting data centers. Contact your Jive Software representative to request this additional service and pricing schedules. Note that this service may require additional lead time depending on the size and traffic of your community.
No. Current SSL solutions typically require no additional machines or hardware and require only a very small amount of CPU resources.