Restricted access to production databases
Access to production databases is limited to authorized personnel with a verified business need and appropriate privileges.
Restricted access to production networks
Privileged access to production networks is granted only to authorized users based on role and business necessity.
Unique authentication enforced
Access to production systems requires unique user authentication, using individual usernames and passwords or approved Secure Shell (SSH) keys.
Encrypted remote access
Remote access to production systems is permitted only through approved, encrypted connections and is restricted to authorized employees.
Log management and monitoring
The company employs centralized log management to detect, analyze, and respond to events that could impact security objectives.
Network segmentation
The production environment is segmented to minimize risk and prevent unauthorized access to customer data.
Employee background checks
Background checks are conducted for all new employees in accordance with applicable laws and regulations.
Contractor confidentiality agreements
All contractors are required to sign a confidentiality agreement prior to engagement.
Employee confidentiality agreements
Employees acknowledge and sign NDA as part of the onboarding process.
Performance evaluations
Managers conduct performance evaluations for their direct reports at least once a year.
Encryption at rest
Customer data stored in company-managed data storage is encrypted at rest.
Control self-assessments
The company performs control self-assessments at least once a year to confirm that security controls are properly designed and operating effectively.
Encryption in transit
Secure transmission protocols are used to encrypt customer data transmitted over public networks.
Vulnerability and system monitoring
The policies define requirements for vulnerability management and continuous system monitoring within IT and Engineering functions.
Configuration management
A configuration management process ensures systems are deployed and maintained in a consistent and secure manner.
Documented organizational structure
The company maintains an up-to-date organizational chart outlining reporting lines and responsibilities.
Defined roles and responsibilities
Information security roles and responsibilities across system design, development, operation, and monitoring are formally documented.
Support and incident reporting
A support system enables users to report incidents, failures, concerns, and other issues to appropriate personnel.
Access provisioning controls
User access to system components is role-based and requires documented approval prior to provisioning.
Customer support resources
Guidelines and technical support resources related to system operations are available to customers.
Service transparency
The company provides clear descriptions of its products and services to both internal and external users.
Risk management objectives
Risk management objectives are defined to support the identification and assessment of risks affecting service commitments.
Risk assessments
Risk assessments are conducted at least once a year, considering environmental, regulatory, technological changes, and potential fraud risks.
Third-party management
Written agreements with vendors and third parties include confidentiality and privacy obligations appropriate to the services provided.
AI and Customer Data
We do not use customer data to train our AI models. Your data is used only to provide and support our services — never for advertising, resale, or unrelated product development.
Customer data deletion
Upon service termination, customer data is securely deleted unless it needs to be stored for the purposes and for the duration required under applicable legislation.