1. Encryption
Data encrypted in transit and at rest, with key management practice described.
How we protect the personal data entrusted to us — encryption, access control, monitoring, testing and incident response.
Draft outline — not yet legally binding. This page lists the sections this document must contain. The operative text needs your legal entity name, registered address and Grievance Officer details, and must be reviewed by counsel before publication. Send us those details and we will complete it.
Data encrypted in transit and at rest, with key management practice described.
Role-based access, least privilege, and time-bound approvals for staff access to customer data.
What is logged, how long logs are kept, and who reviews them.
Cadence of vulnerability scanning and independent penetration testing.
Detection, containment, notification and post-incident review.
Backup, restore testing and recovery objectives.
Questions about this document? Write to [email protected].