SpiderOak's data centers are SAS 70 Type II compliant. Our data center is considered a Tier 3 data center by the Uptime Institute, with N+1 infrastructure, employs the SSAE-16 audit schedule, physically staffed 24/7.
Additionally, SpiderOak matches the requirements set forth by HIPAA and GDPR. The SpiderOak client and server environment contain all the appropriate technical security mechanisms to protect the data that is transmitted to and from the SpiderOak servers. In fact, we built the SpiderOak No Knowledge privacy environment specifically to handle this task. That said, we do not currently employ a HIPAA or GDPR compliance officer for self-certification.
The services provided by SpiderOak do form a critical part of Data Backup, Disaster Recovery, and Emergency Mode Operations strategies by providing remote accessible backup, storage, and restore services that are geographically distant from the client site to minimize the likelihood of data loss in a large-scale disaster. In the event of loss of the primary data center, data located on the SpiderOak cloud can easily, securely and quickly be accessed and restored. Covered entities are required to comply with the HIPAA Administrative Simplification Security Rule since April 21, 2005. SpiderOak, as part of a comprehensive security plan, can be an important part of your compliance strategy.
SpiderOak's datacenters are located in the midwestern United States. Our datacenters have complete security and redundancy to ensure your data is protected from external and internal threats.
If you have any feedback on this article please let our support team know. Thanks!