Customer Security Policy

Application

This Customer Security Policy defines the applicable security requirements that you must follow when accessing the e2open, LLC, our divisions, affiliates and subsidiaries (collectively “e2open”) network. The examples listed in this policy are not exhaustive. e2open reserves the right to remove any content or restrict or terminate your use of the software and services for activities or content if Customer violates this policy or any agreement pursuant to which you use the services. e2open may change this policy from time to time by posting the updated policy on its web site (https://www.e2open.com/customer-security-policy/). You are deemed to accept changes to this policy upon your use of the software and services following any such change. If you do not accept this policy, you may not access e2open’s network or use any of the software and services.

    • Customer must notify e2open when Customer diverges or plans on diverging from “standard industry practices” regarding e2open technology and security;
    • All connections or communications to e2open must be made with a cryptographically secure mechanism, either in the protocol connection or by solution encryption and digital signatures;
    • Exceptions need to be approved in writing by both e2open and Customer’s security representative for the following: (i) production data should not be used in non-production environments; (ii) digital certificates used to interact with e2open must be from certificate authorities trusted in the industry;
    • User identities and passwords used to connect to the e2open environment must be kept strictly confidential;

e2open must be notified immediately in the event of a breach of security involving e2open data;

  • Service accounts used to provide system services must not be used by an individual to log into e2open’s environment;
  • Customer must put adequate procedures in place to ensure that access is removed for Users who are no longer authorized to access the e2open network;
  • Privileges given to Users of e2open applications must be appropriate for their role/position;
  • Users of the e2open network must not enter false or malicious information into e2open’s applications or network;
  • Vulnerability and application testing may be performed by Customer only with prior written consent of e2open;
  • Customer is responsible for verifying the data integrity in Customer’s ERP and other systems, including verification that transactions have been entered completely, accurately, and on a timely basis, which includes reconciling Customer’s ERP and other systems with data and reports based on its use of the e2open solution;
  • Customers should have controls in place and operating effectively, to ensure there is appropriate antivirus protection for their IT environment.
  • Customer needs prior approval to run automated bots on e2open applications

 

This Customer Security Policy was last updated on August 28, 2023.