White Paper. Software as a Service by Yardi. Secure, seamless hosting and support



Similar documents
Secure, Scalable and Reliable Cloud Analytics from FusionOps

Kaseya IT Automation Framework

IBM Cognos TM1 on Cloud Solution scalability with rapid time to value

Symantec Backup Exec.cloud

Interact Intranet Version 7. Technical Requirements. August Interact

Cloud Management. Overview. Cloud Managed Networks

SaaS Security for the Confirmit CustomerSat Software

Perceptive Software Platform Services

Las Vegas Datacenter Overview. Product Overview and Data Sheet. Created on 6/18/2014 3:49:00 PM

custom hosting for how you do business

Hosted SharePoint: Questions every provider should answer

CloudDesk - Security in the Cloud INFORMATION

DISASTER RECOVERY. Omniture Disaster Plan. June 2, 2008 Version 2.0

IT SERVICE MANAGEMENT FAQ

We look beyond IT. Cloud Offerings

Injazat s Managed Services Portfolio

Saf April Saf Helping your business reach further with hosted at UK based, ISO 27001, Tier 4 data centres.

Managed IT Secure Infrastructure Flexible Offerings Peace of Mind

Blackboard Collaborate Web Conferencing Hosted Environment Technical Infrastructure and Security

PROMAPP TECHNICAL INFORMATION

Mapping Your Path to the Cloud. A Guide to Getting your Dental Practice Set to Transition to Cloud-Based Practice Management Software.

KASEYA CLOUD SOLUTION CATALOG 2016 Q1. UPDATED & EFFECTIVE AS OF: February 1, Kaseya Catalog Kaseya Copyright All rights reserved.

Itron Cloud Services Offering

Logicalis Enterprise Cloud Frequently Asked Questions

Delphi 2015 SP1-AP1 System Requirements

Infrastructure as a Service (IaaS) Dancik International and Peak 10

Cloud Management. Overview. Cloud Managed Networks

Hosting Services VITA Contract VA AISN (Statewide contract available to any public entity in the Commonwealth)

Table of Contents. CSC CloudCompute Service Description Summary CSC 1

Compulink Advantage Cloud sm Software Installation, Configuration, and Performance Guide for Windows

Comparing the Cost of Ownership of Physical PCs, VDI, and TetherView Desktops

How To Secure Your Data Center From Hackers

WHITE PAPER SETTING UP AND USING ESTATE MASTER ON THE CLOUD INTRODUCTION

SAS 70 Type II Audits

Security, trust and assurance

REMOTE BACKUP-WHY SO VITAL?

Release Notes. Cloud Attached Storage

The Elite Workforce Management Solution. Driven by People and Technology

Sage Nonprofit Online and Sage Virtual Services. Frequently Asked Questions

Our Cloud Offers You a Brighter Future

SERVICES BRONZE SILVER GOLD PLATINUM. On-Site emergency response time 3 Hours 3 Hours 1-2 Hours 1 Hour or Less

Xerox Digital Alternatives Security and Evaluation Guide. May 2015 Version 1.1

CSC BizCloud VPE Service Offering Summary. CSC i

611 Tradewind Dr. Suite 100, Ancaster ON, L9G 4V5 (905) ext 244

Cherwell Software Hosted Environment

The Business Case Migration to Windows Server 2012 R2 with Lenovo Servers

Created By: 2009 Windows Server Security Best Practices Committee. Revised By: 2014 Windows Server Security Best Practices Committee

SNAP WEBHOST SECURITY POLICY

ACME Enterprises IT Infrastructure Assessment

<cloud> Secure Hosting Services

GiftWrap 4.0 Security FAQ

Library Recovery Center

PROTECTING YOUR VOICE SYSTEM IN THE CLOUD

PREMIER SUPPORT STANDARD SERVICES BRONZE SILVER GOLD

One Solution for Real-Time Data protection, Disaster Recovery & Migration

DEDICATED MANAGED SERVER PROGRAM

Business process efficiency is improved with task management, alerts, notifications and automated process workflows.

Security Controls for the Autodesk 360 Managed Services

Technical Considerations in a Windows Server Environment

Data Storage That Looks at Business the Way You Do. Up. cloud

itg CloudBase is a suite of fully managed Hybrid & Private Cloud Services ready to support your business onwards and upwards into the future.

Delphi+ System Requirements

SWAP EXECUTION FACILITY OPERATIONAL CAPABILITY TECHNOLOGY QUESTIONNAIRE

Storage Guardian Remote Backup Restore and Archive Services

Remote Services. Managing Open Systems with Remote Services

YARDI Investment Suite. Innovative Solutions to Enhance Investor Value

MaaS360 Mobile Service

Information Technology Security Procedures

WINDOWS SERVER SMALL BUSINESS SOLUTIONS. Name: Marko Drev

Woodcock-Johnson and Woodcock-Muñoz Language Survey Revised Normative Update Technical and Data Security Overview

How To Host A Website On A Server At Zen Internet

Cloud Hosting. Quick Guide 7/30/ EarthLink. Trademarks are property of their respective owners. All rights reserved.

SINGTEL BUSINESS - PRODUCT FACTSHEET MANAGED CLOUD SERVICE (SINGTEL IAAS)

OVERVIEW. IQmedia Networks Technical Brief

BMC s Security Strategy for ITSM in the SaaS Environment

Modern Pharmacy IT. R x IT as a service. Kodiak service summary. Service features. Hosted Framework. Hosted DocuTrack

Open Directory. Apple s standards-based directory and network authentication services architecture. Features

DESIGNATED CONTRACT MARKET OPERATIONAL CAPABILITY TECHNOLOGY QUESTIONNAIRE

Powering the Cloud Desktop: OS33 Data Centers

Compulink Advantage Online TM

HP ProLiant Storage Server family. Radically simple storage

Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0

Systems Manager Cloud Based Mobile Device Management

This document and the information contained herein are the property of Bowman Systems L.L.C. and should be considered business sensitive.

CA Cloud Overview Benefits of the Hyper-V Cloud

Data Protection with IBM TotalStorage NAS and NSI Double- Take Data Replication Software

Client Security Risk Assessment Questionnaire

Reform PDC Document Workflow Solution Streamline capture and distribution. intuitive. lexible. mobile

Making the leap to the cloud: IS my data private and secure?

Cloud Vendor Evaluation

Exhibit to Data Center Services Service Component Provider Master Services Agreement

Security and Managed Services

Vistara Lifecycle Management

Antelope Enterprise. Electronic Documents Management System and Workflow Engine

GOVERNANCE AND SECURITY BEST PRACTICES FOR PAYMENT PROCESSORS

Introduction 1 Performance on Hosted Server 1. Benchmarks 2. System Requirements 7 Load Balancing 7

Transcription:

White Paper Software as a Service by Yardi Secure, seamless hosting and support Yardi, the Yardi logo, and the names of Yardi products and services are either registered trademarks or trademarks of Yardi Systems, Inc. Other product and company names mentioned herein are the trademarks of their respective owners. Copyright Yardi Systems, Inc., 2015. All rights reserved. All technical specifications are subject to change. Yardi Systems, Inc. 430 South Fairview Avenue Santa Barbara, California 93117 www.yardi.com

Why Software as a Service? In the Software as a Service (SaaS) delivery model, users access software hosted by a provider over the Internet. SaaS is now the delivery model of choice in all industries, as web-based services and serviceoriented architecture become more sophisticated. In light of the growing capabilities and associated complexity new software offers, SaaS enables organizations to use leading-edge software without the complex burden of hosting it themselves. The same is true for the real estate industry. The SaaS model continues to grow in popularity because of the benefits it offers over self-hosting for real estate managers, owners, and investors who rely on technology to run their business, such as:» Easier application and data administration» Tighter security and better performance» Decreased IT costs» More expedient implementation and more effective technical support» Option for automatic updates or ability to determine when upgrades are applied» Easy, seamless addition of ancillary products and new features By selecting SaaS technology platforms, real estate organizations can focus on their core business and dedicate internal IT staff to innovation and business support. A SaaS provider s ongoing support, highavailability infrastructure, and business continuity services all facilitate more efficiency and higher user productivity, which leads to streamlined operations and ultimately enhances the bottom line. Because a SaaS provider can more easily build out the platform to encompass the real estate business, companies gain the option of consolidating on a single solution stack, which minimizes vendors and creates even more efficiency. Ultimately, these combined benefits allow a company to be more competitive in the marketplace. Yardi delivers software under the SaaS model, supported by the dedicated, in-house Yardi Cloud Services team. We began offering cloud-based solutions in 2000, when we hosted 20 corporate clients. As of 2015, we host more than 4,500 clients via a global data center network. We offer deployment options tailored to each client s organizational needs. Key benefits include: Support and Implementation» SSAE 16-audited hosting operations and data centers» 24-hour IT support working closely with Yardi application support and development» Reduced internal staffing needs and costs to implement, maintain, and support system» Ongoing server monitoring and maintenance» Protection against outdated technology» A support team with more than 15 years of experience hosting Yardi applications for clients Accessibility» Easier administration and standardization across users» 24/7 accessibility from anywhere with an Internet connection» Real-time, centralized processing and reporting on all properties in the portfolio» Scalability to add and remove users and functionality as needed 2

Security» Sarbanes Oxley-compliant controls» Dedicated databases and custom reports for each client» 24-hour monitoring of server operations and data centers» TLS encryption over the Internet» Multiple firewalls and an intrusion prevention system» Anti-virus, anti-malware, and data loss prevention software» Seismically braced server racks» On-premises security personnel and continuous video surveillance» Screening of all people who enter and exit data centers Redundancy and Uptime» Guaranteed 99.5% availability» Redundant hard drives, servers, network clusters, and network devices» Ongoing and nightly backups and off-site transfer of all data» Built-in disaster recovery to a remote recovery data center» Backup battery power and standby generators with automatic failover» Redundant heating, ventilation, and air conditioning» Temperature monitoring, fire detection, and fire suppression systems» Multiple Internet service providers at each data center Yardi SaaS For companies with limited internal IT resources, Yardi SaaS offers cost-effective access to a secure system with skilled application support and 24-hour monitoring, backups, and disaster recovery. Yardi manages ongoing system updates and installs them automatically after 60 days notice. Clients share an installation of the application, but they have their own database and custom reports. We preconfigure environments using internal best practices to optimize security and performance. This expedited deployment meets most business requirements, but clients can subsequently tailor the system to their needs. They have access to a single chart of accounts, as well as to all standard Yardi interfaces. Clients pay no startup fees and receive unlimited application support through a single point of contact (SPOC). Requests for custom programming (CPRs), reports, and script writing are quoted and billed at the applicable hourly rate. Yardi SaaS is ideal for privately held companies managing assets in the United States and Canada. Typical clients manage portfolios of fewer than 5,000 residential units or 1,000 commercial leases. Key Benefits» No user startup costs» Best practices-based pre-configuration» Rapid implementation and deployment (typically six to 12 weeks)» Unlimited application support through SPOC» Automatic product updates twice a year with 60 days notice 3

Yardi SaaS Select Yardi SaaS Select clients can control and modify key aspects of the system while benefiting from Yardi s site and server management and disaster recovery services. Clients have a dedicated application installation, determine their own software update schedules, and can use multiple charts of accounts. Yardi hosts the software in a shared network environment optimized for performance and security. Dedicated virtual servers and premium disaster recovery are available for an additional fee. Yardi SaaS Select accommodates a wide variety of client needs. It is an excellent choice for medium to large businesses, publicly traded organizations, investment managers, and government agencies. Medium-sized property managers may choose this model to gain additional flexibility. Key Benefits» Control over software upgrades and updates» Less demand on internal IT resources than self-hosting» Optional single sign-on via SAML 2.0 identity provider Yardi Private Cloud Yardi Private Cloud clients have their own database and application as well as VPN connectivity to the Yardi Cloud. This deployment model includes dedicated virtual servers throughout. Yardi manages and maintains Yardi Voyager servers, but clients can manage their own web and database servers to run non-yardi applications in their Private Cloud. Effectively replicating a self-hosted environment, this option offers superior hardware and 24/7 service. Yardi Private Cloud is appropriate for large, global, or publicly traded organizations, investment managers, and government agencies with complex control needs. Organizations looking to replace an internal data center that hosts multiple business applications can benefit from Yardi s infrastructure and seamless Yardi Voyager support. Key Benefits» Option to use third-party applications on client-managed servers» Virtual Private Network (VPN) tunneling and vlan for added security Infrastructure IT Staff Crucial to the success of our SaaS platform is the Yardi Cloud Services team. Our growing team of more than 100 Yardi professionals ensures rotating 24-hour coverage of Yardi s data centers. Clients receive 24/7 technical assistance via our hosting hotline. The team also supports, maintains, and monitors application servers, database servers, and the network. Hardware and Software Yardi hosting uses Dell hardware in combination with multiple firewalls, hardware load balancing, and the latest Yardi-qualified versions of Microsoft IIS (Internet Information Services), RDP, Windows 4

Server, and SQL Server. All hardware and software runs parallel, providing 24-hour data access in a high-availability environment. To access their Yardi software, users only need a device with an Internet connection and browser. Routine Maintenance Yardi hosting staff monitors updates for all software and hardware used in the cloud environment. We implement these patches as follows:» Validate the patch in a test environment» Implement the patch in a limited beta environment (with management approval)» Apply the patch to production environments on a rotating basis (with management approval) Service Level Goals Yardi hosting operates under the following service level benchmarks: Site Availability Metric Goal Network Availability» LAN» WAN (ISP access) Network uptime 99.5% System Availability System uptime 99.5%» Operating systems» Servers» Storage devices» Switches» Load balancers» Routers» Firewalls Application Availability Application uptime 99.5%» Voyager» Orion» Beacon» Point2 products» PropertyShark» RENTCafé To meet service level goals, we use specialized tools to track performance-related statistics, including memory utilization, CPU, and disk space. If acceptable performance parameters (as defined in the Service Level Agreement) are ever not met, a wireless alert notifies the appropriate team member. As an additional failsafe, we perform weekly accessibility testing. Partners To ensure redundancy and minimize risk, we partner with carefully selected providers of data center space, such as CenturyLink (formerly Savvis) and SunGard. We replicate data stored at any of our active centers automatically at a regional sister site, so any corrupted or destroyed data at an active site can be restored by transferring a copy from the standby site over the network. 5

Security Comprehensive security features and procedures safeguard Yardi clients data. Site security at data centers includes on-premises security personnel, continuous video surveillance, screening of all people entering or exiting the premises, seismically braced server racks, high-tech fire suppression systems, and round-the-clock monitoring of server operations. In addition, we contract with third-party security experts to perform penetration tests of the network and application. Our security model includes the following layers:» Transport Layer Security (TLS). Data sent over the Internet is always encrypted.» Intrusion Prevention Systems and Multiple Firewalls. These control the type of information that is transmitted and received by data center servers. In 2015 we are enhancing our security with next-generation and web application firewalls as well as data loss prevention software.» Virus and Malware Protection. Real-time anti-virus and anti-malware software safeguards all Yardi servers.» Active Directory Security. This ensures that all users have access only to their organization s specific applications. Folder access is based on company-defined permissions.» Database Authentication and Name Encryption. The system authenticates any attempt to log in to the database server. Database names are encrypted to ensure client anonymity. File-level encryption via Transparent Data Encryption (TDE) is available in 2015.» User-Defined Access. Your system administrator can authorize users from within the program to access program features and reports and can define idle periods for session timeouts.» User-Defined Password Expiration. Your organization s system administrator can define how often system passwords must be changed to conform to internal protocol. 6

Sarbanes-Oxley For clients who require tighter controls, we have implemented multiple processes to ensure data integrity. Many of these aid clients in fulfilling the stated objective of the Sarbanes-Oxley Act, to protect investors by improving the accuracy and reliability of corporate disclosures made pursuant to the securities laws. Every Yardi data center has, at a minimum, the following controls in place:» Co-location of client data at a SSAE 16-audited facility» On-premises security personnel» Continuous video surveillance» Screening of all people entering/exiting the premises Additional internal Yardi controls available to Sarbanes-Oxley-obligated clients include:» Requiring written client approval to implement any change to the production environment» Stringent controls governing user access to client data» Monitoring and reporting on client custom files» Segregation of Yardi Cloud Services personnel job functions to ensure data integrity» SSAE 16 service auditor s reports An additional fee may apply for certain levels of data protection. Redundancy Site and Network Redundancy Backup generators at each data center ensure uninterrupted power supply (UPS) in the event of power failures. Similarly, data centers have redundant heating, ventilation, and air conditioning (HVAC) so that hardware failure will not compromise the controlled server environment essential for optimal system performance. In addition, multiple tier one carriers and Border Gateway Protocol (BGP) connectivity ensure uninterrupted Internet access for each data center. System Backups We store applications and linked files on redundant arrays of independent disks (RAID) and replicate every database on a separate hard drive, which, in turn, is replicated on a server. Multiple independent network clusters provide another layer of redundancy. We replicate client databases with a high level of redundancy for security, integrity, and availability. Each client s database is replicated in real time to a parallel database server with automatic failover capabilities. Incremental transactional backups allow for point-in-time database restores. Optional backup encryption is available. We make complete backups every night and place them on a secure FTP server, from which clients can authorize an internal user to download these backups. Storage media backups are kept in a secure, off-site location whose security is reviewed annually at a minimum. 7

Business Continuity Plan Yardi replicates transactions and default paths for every live client database to a designated standby server at a geographically remote sister center, using a secure VPN connection. Our recovery point objective (RPO) in case of a major incident is two hours. We will restore client data within eight hours; this recovery time objective (RTO) can be reduced to four hours for an additional fee. Scalability A key benefit of our SaaS platform is the ease with which clients can increase processing capacity as their business grows. Our data centers maintain excess capacity at all times, so clients can add users, properties, and functionality quickly as demands increase. No matter how rapidly our clients grow, there are always enough servers on the Yardi network to meet their needs. Conversely, if clients ever need to scale back their operations, they can do so without suffering a loss of investment in unused software and hardware. Centralized Processing Another major benefit of Yardi hosting lies in its centralized database and real-time processing. Yardi s seamless integration of client data with single-stack property, investment management, and financial reporting applications is the ideal solution for a mobile or distributed workforce. Authorized remote users can access up-to-the-minute reporting and post real-time transactions for an entire portfolio. In effect, Yardi hosting lets you run your business as if all of your offices were under one roof, increasing your organization s efficiency and profitability. Client Requirements The following are minimum specifications for users accessing Yardi Voyager 7S as of February 2015. Please see www.yardi.com/services/document-library/section/system-requirements for full details.» Operating System. Microsoft Windows Vista Business or Ultimate, 7, 8, or 8.1; or Apple OS X 10.6 or later; or Apple ios 5 or later; or Android 3 or later» PC Processors. Intel Dual Core, Intel Pentium, AMD, or compatible, 1 GHz or faster» PC Memory. 2 GB RAM» Network. Internet connection, 100 Kbps/user 8