Security and Infrastructure Overview
At Grapevine, ensuring the security, confidentiality, and integrity of your data is paramount. Our services are hosted on secure, private cloud infrastructure provided by F12.net, a Canadian managed IT services leader with a SOC 2 Type II attestation. This strategic partnership allows us to deliver robust security, continuous availability, and compliance with industry standards. Security documentation is available to qualified customers and prospects under a non-disclosure agreement upon request.
Data Center Security
Our applications and data are hosted in secure Canadian data centers managed by F12.net. These state-of-the-art facilities comply with stringent security, regulatory, and availability standards. Physical security includes biometric authentication, controlled access, CCTV surveillance, and multi-zoned fire suppression systems. Facilities also feature redundant power supplies, including backup generators and uninterruptible power supply (UPS) systems, redundant cooling systems to maintain optimal environmental conditions, and continuous 24/7 monitoring by dedicated Network Operations Center (NOC) personnel. Additionally, these data centers utilize multiple network carriers, enabling automatic cutover in the event of physical or network disruptions affecting a primary carrier.
Network and Endpoint Protection
We utilize comprehensive endpoint protection and network security measures, including advanced endpoint detection and response technologies, centrally managed antivirus and malware prevention, Data Loss Prevention (DLP) technologies, secure access controls with multi-factor authentication, and continuous monitoring. Regular third-party penetration tests are conducted to ensure ongoing security effectiveness.
Business Continuity and Disaster Recovery
We leverage F12.net's robust business continuity services, enabling seamless service transition between geographically dispersed Canadian data centers (Eastern and Western Canada). This capability ensures rapid recovery, minimal disruption, and consistent availability of our services even in the event of a significant operational impact. Recovery objectives and detailed continuity procedures are available to customers under a non-disclosure agreement upon request.
Backup and Data Protection
Regular encrypted backups are conducted according to secure retention policies, ensuring data integrity and availability for restoration purposes. All backups remain encrypted both in transit and at rest. Specific backup frequency and retention details are available to customers under a non-disclosure agreement upon request.
Application-Level Security
Our application incorporates multiple layers of security to protect customer data:
- Customer data is encrypted both in transit (SSL/TLS) and at rest.
- Each customer's data is logically separated within our environment and protected by appropriate access controls to maintain tenant isolation.
- Strong password policies are enforced, with all passwords securely hashed and salted. Authentication sessions are managed using secure, encrypted tokens; passwords are never stored within session or authentication cookies.
- Payment transactions are securely handled by Moneris, a trusted PCI-DSS compliant third-party payment provider. No credit card data is collected or stored within Grapevine's systems.
- Secure data deletion procedures are in place, with clear processes for customers to request deletion of their data. Account-wide deletion requests are processed within 30 days. Deleted data may persist in encrypted backups for up to 104 days before permanent removal.
For further information about our security practices, or to request security documentation, please contact dataprotection@grapevineevaluations.com.
Revised June 23, 2026