We are trying to create a new application that will use Genesys Cloud API endpoints for reporting purposes.
In order to achieve this, our security department has come back with some questions, listed below:
- All endpoints sit behind WAF and anti attack DDoS protection
- The API uses a forced HHTPS forced cypher channel. What TLS certificates does it accept.
- Provide evidence of periodic vulnerability scans.
- Verification of additional security controls, such as limiting the access to the API to certain IPs
- A way to audit API connections from the Genesys Cloud dashboard.
We would need to provide evidences of all these points through documentation or screenshots.
Can you please provide them?