{"id":23324,"date":"2021-01-27T10:22:46","date_gmt":"2021-01-27T10:22:46","guid":{"rendered":"https:\/\/support.etool.app\/?page_id=23324"},"modified":"2026-07-06T09:01:16","modified_gmt":"2026-07-06T09:01:16","slug":"etool-reliability-and-security","status":"publish","type":"page","link":"https:\/\/support.etool.app\/index.php\/etool-reliability-and-security\/","title":{"rendered":"eTool Reliability and Security"},"content":{"rendered":"\n<h1>Solution Overview<\/h1>\n<p>eTool is a web application hosted with Amazon Web Services (AWS).\u00a0 The application server itself runs on an EC2 Windows machine and is connected to a MySQL database running on the AWS RDS services.\u00a0 AWS S3 is used for document storage (reports and uploaded documents).\u00a0 A small number of external services are utilised for subscription management, transactional email and geolocation services.\u00a0 See the below basic architecture diagram:\u00a0<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-23325\" src=\"https:\/\/support.etool.app\/wp-content\/uploads\/2021\/01\/eToolLCD-High-Level-Architecture-Diagram-2020-eToolLCD-High-Level-Architecture-1.png\" alt=\"\" width=\"576\" height=\"511\" srcset=\"https:\/\/support.etool.app\/wp-content\/uploads\/2021\/01\/eToolLCD-High-Level-Architecture-Diagram-2020-eToolLCD-High-Level-Architecture-1.png 576w, https:\/\/support.etool.app\/wp-content\/uploads\/2021\/01\/eToolLCD-High-Level-Architecture-Diagram-2020-eToolLCD-High-Level-Architecture-1-300x266.png 300w\" sizes=\"auto, (max-width: 576px) 100vw, 576px\" \/><\/p>\n<h1>Infrastructure<\/h1>\n<p>The solution is hosted primarily in AWS Dublin Data centres with backups hosted in Frankfurt.\u00a0 For details on AWS Security responsibilities and controls see below links:\u00a0<\/p>\n<ul>\n<li><a href=\"https:\/\/aws.amazon.com\/compliance\/programs\/\">Standards Compliance<\/a><\/li>\n<li><a href=\"https:\/\/d1.awsstatic.com\/whitepapers\/Security\/Intro_to_AWS_Security.pdf?did=wp_card&amp;trk=wp_card\">AWS Security Introduction White Paper<\/a><\/li>\n<\/ul>\n<p>AWS specifically manage the following aspects:<\/p>\n<ul>\n<li>Data centre security<\/li>\n<li>Data at rest physical protection<\/li>\n<li>Data sanitisation at customer&#8217;s request<\/li>\n<li>Equipment disposal and effective sanitisation<\/li>\n<li>Physical resilience and availability<\/li>\n<\/ul>\n<h3>eTool Service Configuration<\/h3>\n<p>Cerclos has configured our AWS environment following best practices as follows:\u00a0<\/p>\n<ul>\n<li>All data is encrypted at rest<\/li>\n<li>Ports are closed by default and carefully managed so that only recognised traffic may access the server<\/li>\n<li>Data is encrypted in transit using modern TLS allowing maximum security (pending browser&#8217;s capabilities)\u00a0<\/li>\n<li>The application stack is entirely housed within the Virtual Private Cloud and any access is managed via AWS Identity Management with two factor authentication<\/li>\n<\/ul>\n<h3>Cerclos Infrastructure Security Management<\/h3>\n<p>Some activities within the application life cycle are conducted outside of the AWS infrastructure such as product development.\u00a0 Cerclos manages the risk of these activities in the following fashion:<\/p>\n<ul>\n<li>Where possible data is synonymised on our test and development environments to further protect user data<\/li>\n<li>Data is encrypted at rest<\/li>\n<li>Staff are:\n<ul>\n<li>background-checked<\/li>\n<li>Trained in IT security<\/li>\n<li>Required to sign NDAs<\/li>\n<li>Accountable to the following policies:\n<ul>\n<li>Acceptable Use Policy<\/li>\n<li>Personal and Sensitive Data Protection Policy<\/li>\n<li>Password Management Policy<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>Password strength, age and uniqueness are audited<\/li>\n<li>Our server is configured to resist denial of service attacks<\/li>\n<\/ul>\n<h1>Security Risk Mitigation<\/h1>\n<p>Regular independent penetration testing is conducted by an ethical hacker.\u00a0 The scope of works includes deep manual threat investigation and assessment, reporting on potential vulnerabilities and retesting of required fixes.\u00a0 Fixes to security threats are prioritised in our backlog.\u00a0\u00a0<\/p>\n<p>eTool utilises a multi-tenant database.\u00a0 This is a conscious decision to improve the value of the platform as users can choose to contribute building component information to the platform which greatly increases the available component data for all users.\u00a0 Cerclos has developed the following strategies to mitigate the risk to customer&#8217;s data security:\u00a0<\/p>\n<ul>\n<li>Dedicated authentication and access management controller within the app via which all requests are submitted<\/li>\n<li>The authentication and access management controller is subject to in-depth automated front-end regression testing prior to each release<\/li>\n<li>Administrator rights are carefully managed and audited<\/li>\n<li>Requests are validated in both the front end and application server<\/li>\n<li>The scope of penetration testing includes deliberate attempts to bypass security controls by any means<\/li>\n<li>Audit logs are maintained for most database transactions so that evidence of data privacy breaches is available<\/li>\n<li>Users are required to provide 2 Factor authentication when the application detects changes to their environment or location<\/li>\n<\/ul>\n<h1>Accessibility<\/h1>\n<p>eTool is available on modern browsers.\u00a0 It is best used on laptop or desktop machines.\u00a0 It can be used on tablets and mobiles but has not been designed specifically for this purpose and hence text size etc is likely to be an issue.\u00a0\u00a0<\/p>\n<p>The application generally requires very low bandwidth with the exception being uploading, rendering or downloading large reports or documents which is a relatively low frequency task by most users.\u00a0 1Mbps up will be more than adequate for most use cases.\u00a0 The application runs well in all regions despite the distance from the server (Ireland) and as such latency is rarely a noticeable issue.\u00a0 \u00a0<\/p>\n<p>eTool is built with modern and popular web technologies and complies with many accessibility standards however we have not been formally audited for compliance.\u00a0 There may be some specific controls and components within the user interface that may not be easily navigated by persons with disabilities.\u00a0\u00a0<\/p>\n<h1>Scaleability<\/h1>\n<p>The application software and hardware is readily scaleable.\u00a0 We currently have over 5000 users, the app is often used by universities in training where upwards of 100 students will be accessing the application simultaneously without significant affect on performance.\u00a0\u00a0<\/p>\n<p>Cerclos monitors performance in a number of ways.\u00a0 High level performance monitoring (infrastructure stress) is monitored via AWS Cloudwatch (see incident response for more details).\u00a0 \u00a0Where hardware bottlenecks are identified AWS provides solutions to scale quickly.\u00a0\u00a0<\/p>\n<p>The development team monitor the performance of application\u00a0 at a very detailed level (controller requests and responses) to prioritise and improve the application itself.\u00a0 This performance monitoring solution runs continuously and the logs are periodically reviewed to identify improvement opportunities.\u00a0\u00a0<\/p>\n<h1>Code Quality and Release Management<\/h1>\n<p>eTool code quality is managed through a number of procedural and systematic controls.\u00a0 Staff are trained in new technology as it is introduced to the stack.\u00a0 The code is managed in a Git repository and the development team follow detailed procedures for branching, commits and pull requests to ensure the development life cycle enables relevant testing and review cycles to be completed.\u00a0<\/p>\n<p>During development Resharper is used to improve the quality, consistency and readability of the code.\u00a0 Code reviews are conducted for each pull request.\u00a0 Acceptance testing of the changes is also conducted at this point in dedicated test environments.\u00a0 Once the code review is complete (including required changes) a release candidate is compiled and deployed to our pre-production environment.\u00a0 Comprehensive regression automated testing (front end) using Selenium is run on the pre-production environment prior to release.\u00a0\u00a0<\/p>\n<p>All deployments are managed with Team City to reduce scope for human error.\u00a0\u00a0<\/p>\n<h1>Incident Response<\/h1>\n<p>eTool has a comprehensive Disaster Recovery Plan which spans the backup strategy, backup strategy, disaster response plan and post recovery actions.\u00a0 This document is available upon request.\u00a0<\/p>\n<p>Key points in the plan include:<\/p>\n<ul>\n<li>Cerclos proactively monitors the health of the solution with AWS Cloudwatch.\u00a0 Thresholds are set for infrastructure health and when these are reached alarms are triggered notifying staff via email and SMS message.\u00a0\u00a0<\/li>\n<li>Backups are taken at 3 hourly intervals and snapshots of our application and database are maintained appropriate intervals indefinitely<\/li>\n<li>Backups are stored in the Ireland data centre and cloned to Franfurt for redundancy<\/li>\n<li>Detailed recovery procedures are included in the plan to reduce key person risk<\/li>\n<li>Post recovery actions include communication of potential data losses to customers as well as reconfiguration of the recovered environments<\/li>\n<\/ul>\n<p>Disaster recovery simulations have demonstrated an ability to recover the solution from backups in under 30 minutes.\u00a0\u00a0<\/p>\n<h1>Target Service Levels<\/h1>\n<p><img decoding=\"async\" src=\"https:\/\/etoolglobal.com\/wp-content\/uploads\/2012\/09\/SLA-Table.png\" alt=\"SLA Table\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Solution Overview eTool is a web application hosted with Amazon Web Services (AWS).\u00a0 The application server itself runs on an EC2 Windows machine and is connected to a MySQL database running on the AWS RDS services.\u00a0 AWS S3 is used for document storage (reports and uploaded documents).\u00a0 A small number of external services are utilised [&hellip;]<\/p>\n","protected":false},"author":29,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"footnotes":""},"class_list":["post-23324","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/support.etool.app\/index.php\/wp-json\/wp\/v2\/pages\/23324","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/support.etool.app\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/support.etool.app\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/support.etool.app\/index.php\/wp-json\/wp\/v2\/users\/29"}],"replies":[{"embeddable":true,"href":"https:\/\/support.etool.app\/index.php\/wp-json\/wp\/v2\/comments?post=23324"}],"version-history":[{"count":10,"href":"https:\/\/support.etool.app\/index.php\/wp-json\/wp\/v2\/pages\/23324\/revisions"}],"predecessor-version":[{"id":38727,"href":"https:\/\/support.etool.app\/index.php\/wp-json\/wp\/v2\/pages\/23324\/revisions\/38727"}],"wp:attachment":[{"href":"https:\/\/support.etool.app\/index.php\/wp-json\/wp\/v2\/media?parent=23324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}