INFORMATION SECURITY POLICY

Last Updated: July 13, 2025

1. Purpose

To protect the confidentiality, integrity, and availability of information assets.

2. Access Control

  • Role-based access control (RBAC)
  • Least-privilege enforcement
  • Access restricted to authorized personnel

3. Data Protection

  • Encryption in transit using TLS 1.2+
  • Encryption at rest using industry-standard mechanisms

4. Infrastructure Security

  • Segregation of production and non-production systems
  • Logging and monitoring for security events

5. Incident Response

Security incidents are investigated and remediated promptly, with notifications as required.

6. Review

This policy is reviewed periodically.

Security Questions?
If you have any questions about our security practices, please contact our security team.
STAGING