Security and connection overview

Robin connects to Exchange with Microsoft's proprietary secure authentication protocol, "NTLM". With NTLM, Robin stores Exchange authentication credentials with one-way encryption (called "hashing"), so a user's Exchange password is never stored in plain text. To learn more, see how to set up NTLM in Exchange.

Options for allowlisting

You can match user agents containing "RobinAPI", which look like RobinAPI/123456.

For outgoing connections, you can allow Robin's DNS (for example, *.robinpowered.com), which is signed with DNSSEC.

With DNSSEC, you do not need to allow specific IP addresses. The DNS record itself is secured, and you can validate it like an SSL certificate. To confirm, use the DNSSEC tool from Verisign.

What data Robin syncs

After you connect an Exchange service account, the Robin cloud service connects to your Exchange service and starts to sync its data with Robin. Robin saves a subset of your calendar events and their details. These details include event titles, descriptions, start and end dates and times, the location and the list of attendees. Robin does not sync attachments.

Robin then keeps this data in sync with your Exchange service. Events booked through Robin sync back to your Exchange service, so the data in Robin and in Exchange match 1-to-1.

Control which fields sync

Robin syncs the standard fields in the iCal spec so that it works with most calendar systems. To keep Robin from accessing some fields (for example, description, title or invitees), control this in Exchange. With EWS roles, you can strip out fields before Exchange sends them to third parties. See an example of how to strip event fields in EWS.

This approach may limit some event features in Robin (for example, changing the meeting title or invitees), because Robin cannot access that information.

Filter calendar data before it syncs

Robin stores events as it receives them. Robin offers some ways to control how much information shows in the employee apps. If your security controls require that some fields never sync, the most secure method is to handle this at the source (Exchange EWS), not at the application layer.

How Robin stores connection information

Robin accounts never store any plain-text password information. Robin also stores your Robin account password with one-way encryption when you register. It runs your password through a strong crypto-secure hashing algorithm called "bcrypt" with a crypto-secure, randomly generated "salt".

Robin mobile and web apps always connect to the Robin web service over an encrypted, secure connection (SSL/TLS HTTPS). Data between your phone or browser and Robin is never sent or received in plain text. This stops "sniffers" on public or WiFi networks from intercepting data in transit.

Robin is a hosted cloud service and needs no on-premise installation. For specific security implementation questions, ask your account representative.

For more information, see Robin's security and privacy policies.

Related articles

Articles in this section

Was this article helpful?
1 out of 7 found this helpful
Share