Friday Inc.

Security Policy

Last Updated:  Feb 27, 2024

We take security and privacy seriously.

Company security

All developers undergo secure coding training.

Least privilege principle applied for all access, passkey use is prioritized as is multifactor authentication and consistent password manager use A cybersecurity program centered on risk assessment, which includes a risk register and an active Incident Management program.

System security

All data encrypted in transit (TLS 1.2) and at rest (AES-256)

Highly-available, secure, horizontally scalable infrastructure hosted in AWS private subnets, no public IP addresses, no direct internet reachability.

All web interactions use standard browser security headers.

Comprehensive application health and performance monitoring, logging and alerting mechanisms.

A Web Application Firewall (WAF) checks and filters all user-entered data, reducing the risk of security breaches

If you have any questions about our privacy practices or this Privacy Policy, or to exercise your privacy rights as detailed in this Privacy Policy, please contact us at:

FRIDAY INC

Attn: Privacy Program Director

97 South 6th St.

Brooklyn, NY 11249

Security@Friday.com

Tel: 810-374-2391