Security Policy
Last Updated:
At Ingeri Tech Ltd, security is not an afterthought—it is a foundational pillar of our service delivery. We are committed to protecting the confidentiality, integrity, and availability of your data through a comprehensive, multi-layered security framework. This Security Policy outlines the technical, organizational, and procedural measures we implement to safeguard your information against unauthorized access, accidental loss, cyber threats, and other vulnerabilities. We continuously evolve our security posture to address emerging risks while ensuring compliance with international standards and regulatory requirements.
1. Security Philosophy
At Ingeri Tech Ltd, our security philosophy is rooted in the principles of proactive risk management, continuous improvement, and a commitment to safeguarding our clients' data. We believe that security is not just a technical requirement but a core aspect of our organizational culture.
1.1. Security by Design
Security is built into our products, platforms, and operational processes from the earliest planning stages. We evaluate architecture, data flows, access points, and deployment environments before implementation to reduce risks before they materialize.
1.2. Risk-Based Approach
We prioritize security investments based on the likelihood of threats and the potential impact to confidentiality, availability, and business continuity. This helps us focus resources where they matter most.
| Risk Area | Example Threat | Response Approach |
|---|---|---|
| Access management | Unauthorized login | MFA, RBAC, and monitoring |
| Data handling | Data leakage | Encryption and restrictive permissions |
| Infrastructure | Service disruption | Redundancy, backups, and incident response |
1.3. Continuous Improvement
We review our security controls regularly and adapt them to new technologies, regulatory expectations, and emerging threat patterns. Security remains an active discipline rather than a static checklist.
Security controls are reviewed periodically to ensure they remain effective, relevant, and aligned to current threats.
2. Technical Security Measures
Our technical security measures are designed to protect systems, data, and services at multiple layers, from the endpoint to the network and application stack.
2.1. Access Control and Authentication
2.1.1. Multi-Factor Authentication (MFA)
We enforce MFA for administrative and sensitive user accounts to reduce the risk of account compromise. This adds an additional verification factor beyond a password.
2.1.2. Role-Based Access Control (RBAC)
Permissions are assigned based on responsibilities and job requirements so that users only access the systems necessary for their role.
2.1.3. Least Privilege Principle
We apply the least privilege principle to limit access, reduce exposure, and minimize the impact of accidental misuse or malicious activity.
- Administrative accounts are monitored and restricted to authorized personnel.
- Privileged access is reviewed regularly and revoked when no longer required.
- Access reviews are performed periodically across core systems and services.
2.2. Data Encryption and Secure Transmission
2.2.1. Encryption at Rest
Sensitive data stored in databases, file systems, backups, and cloud storage is encrypted to protect it from unauthorized disclosure.
2.2.2. Encryption in Transit
Data transmitted between users, applications, APIs, and cloud services is protected using strong encryption protocols.
2.2.3. Secure Protocols (TLS/SSL)
We use TLS/SSL to secure communication channels and ensure the integrity and confidentiality of information exchanged over the internet.
2.3. Network Security and Firewalls
2.3.1. Intrusion Detection and Prevention Systems (IDPS)
We deploy monitoring and protection systems that detect suspicious activity and help prevent or contain security incidents in real time.
2.3.2. Virtual Private Networks (VPNs)
VPNs are used to secure remote access and protect communications transmitted over less trusted networks.
2.3.3. Network Segmentation
Critical systems are segmented to limit lateral movement and reduce the impact of a compromise within one part of the environment.
2.4. Endpoint Security and Anti-Malware
2.4.1. Anti-Virus and Anti-Malware Solutions
Our devices are protected by anti-malware technologies that identify and block known threats before they spread across our environment.
2.4.2. Endpoint Detection and Response (EDR)
EDR capabilities help us investigate suspicious behavior, contain malicious activity, and improve response time to incidents.
2.4.3. Device Hardening and Patch Management
Devices are hardened through configuration baselines, software updates, and policy enforcement to minimize avoidable attack surfaces.
3. Organizational Security Controls
Technology alone cannot ensure security; strong organizational controls, people, and governance processes are equally important.
3.1. Security Policies and Procedures
We maintain formal policies covering access, data handling, incident response, acceptable use, and change management. These controls are reviewed and approved through management processes.
3.2. Employee Training and Awareness
Employees receive periodic security awareness training to recognize phishing attempts, avoid unsafe practices, and understand their responsibilities in protecting company resources.
3.3. Vendor and Third-Party Management
We assess third parties before onboarding them and review their security posture where they handle or process our data.
- Due diligence reviews are carried out before providers are engaged.
- Security expectations are included in contracts and service agreements.
- Ongoing monitoring helps ensure third parties continue to meet expectations.
Third-party controls are reviewed regularly so that outsourced risk remains visible and manageable.
| Review Area | What We Check | Why It Matters |
|---|---|---|
| Security posture | Policies, controls, and certifications | Confirms the provider can meet baseline expectations |
| Data handling | Storage, transfer, retention practices | Reduces exposure of client information |
| Continuity | Backup and recovery capabilities | Supports resilience and service reliability |
4. Data Encryption Standards
We implement encryption standards that align with industry best practices to protect sensitive data both at rest and in transit.
Encryption is one of the foundational controls used to preserve confidentiality and protect sensitive information throughout its lifecycle.
4.1. Encryption Protocols
4.1.1. AES-256 Encryption
AES-256 is used for strong symmetric encryption where appropriate, providing a high level of protection for stored and transmitted data.
4.1.2. RSA and Public Key Infrastructure (PKI)
RSA and PKI-based mechanisms support secure key exchange, digital signatures, and identity assurance.
4.1.3. Secure Hash Algorithms (SHA-2/SHA-3)
Hashing algorithms are used to verify integrity and support secure authentication workflows.
| Encryption Type | Use Case | Purpose |
|---|---|---|
| AES-256 | Stored data | Protects data at rest |
| TLS 1.2/1.3 | Web traffic | Protects data in transit |
| SHA-2/SHA-3 | Integrity checks | Ensures unchanged content |
4.2. Key Management Practices
4.2.1. Key Generation and Storage
Encryption keys are generated and stored using secure management processes to prevent unauthorized access or compromise.
4.2.2. Key Rotation and Expiration
Keys are rotated periodically to reduce the risk of prolonged exposure in case of compromise.
4.2.3. Secure Key Distribution
Key distribution is handled through controlled channels and approved procedures to protect the confidentiality of material keys.
4.3. Data at Rest and in Transit
4.3.1. Database Encryption
Databases are protected using encryption controls that reduce the risk of exposure if storage media or backups are accessed without authorization.
4.3.2. File System Encryption
Sensitive files are encrypted at the file system level to strengthen protection for local and network-based storage.
4.3.3. Secure Communication Channels
Communication between services and users is secured through encrypted channels and authenticated endpoints.
5. Infrastructure and Network Security
Our infrastructure is designed with security in mind, using layered controls to limit exposure and maintain operational resilience.
5.1. Secure Network Architecture
Network architecture is planned to separate critical systems, reduce unnecessary exposure, and support secure access patterns.
5.2. Firewalls and Intrusion Detection Systems
Firewalls and intrusion detection systems are used to monitor traffic, block malicious activity, and ensure that only authorized connections are permitted.
5.3. Regular Security Audits and Penetration Testing
We conduct regular audits and penetration tests to identify weaknesses before they can be exploited and to validate the effectiveness of existing controls.
Security testing is an ongoing practice and is used to strengthen both preventive and detective controls.
6. Incident Response and Breach Management
We maintain a structured incident response framework to detect, contain, and recover from security incidents with minimal disruption.
6.1. Incident Response Plan
The incident response plan defines roles, escalation paths, communication channels, and steps for triage and containment.
6.2. Breach Notification Procedures
In the event of a suspected or confirmed breach, we follow established procedures for assessment, notification, and remediation in line with applicable legal and contractual obligations.
6.3. Post-Incident Analysis and Reporting
Every incident is reviewed to determine the cause, refine response procedures, and reduce the likelihood of recurrence.
| Phase | Action | Objective |
|---|---|---|
| Detection | Identify and confirm the issue | Reduce response time |
| Containment | Isolate affected systems | Limit impact |
| Recovery | Restore services and verify integrity | Return to normal operations |
7. Vulnerability Management and Testing
We use regular scanning, testing, and review practices to identify and address vulnerabilities before they can be exploited.
7.1. Regular Vulnerability Scanning
7.1.1. Automated Scanning Tools
Automated tools are used to detect known weaknesses across systems, applications, and networks.
7.1.2. Manual Penetration Testing
Manual testing helps uncover issues that may not be visible through automated scans alone.
7.1.3. Remediation and Patch Tracking
Findings are tracked through remediation workflows to ensure timely resolution and validation.
7.2. Patch Management and Updates
Software and systems are updated promptly to protect against known vulnerabilities and to maintain operational stability.
7.3. Security Testing and Quality Assurance
Security checks are incorporated into quality assurance and release processes to reduce the risk of introducing vulnerabilities during change.
8. Third-Party Security Assurance
We evaluate the security posture of external vendors and service providers to reduce risk throughout the supply chain.
8.1. Vendor Security Assessments
New vendors are reviewed for relevant security capabilities, compliance posture, and data handling practices before engagement.
8.2. Third-Party Risk Management
We monitor third-party risks continuously and adjust oversight based on sensitivity, criticality, and observed performance.
8.3. Service Level Agreements and Security Clauses
Security obligations are written into agreements where applicable, including incident handling, confidentiality expectations, and service continuity commitments.
- Security responsibilities are clarified in contractual documents.
- Service providers are expected to support breach reporting and remediation cooperation.
- Critical providers may be subject to additional monitoring and review.
9. Employee Security Training
People are a critical layer of defense, and secure behavior is reinforced through training and policy awareness.
9.1. Security Awareness Training
Employees receive regular training covering phishing awareness, password hygiene, safe data practices, and reporting channels for suspicious activity.
9.2. Role-Based Security Training
9.2.1. Technical Staff Training
Technical personnel receive deeper training on secure configuration, systems monitoring, incident handling, and change control.
9.2.2. Non-Technical Staff Training
Non-technical staff are trained on acceptable use, data confidentiality, and how to respond to suspicious communications or requests.
Security awareness is reinforced regularly so that users remain alert to evolving threats and best practices.
10. Business Continuity and Disaster Recovery
We prepare for disruptions so that essential services can continue or recover rapidly in the event of a major incident.
10.1. Business Continuity Planning
Business continuity plans define how critical operations are maintained during outages, emergencies, or other interruptions.
10.2. Disaster Recovery Strategies
10.2.1. Data Backup and Recovery
Regular backups are maintained and tested so that data can be restored in a timely and reliable manner.
10.2.2. Redundancy and Failover Mechanisms
Where appropriate, systems are designed with redundancy and failover capabilities to maintain availability during failures.
10.3. Regular Testing and Drills
We test business continuity and disaster recovery procedures regularly to validate readiness and identify improvement opportunities.
| Area | Primary Goal | Example Measure |
|---|---|---|
| Backup | Restore data quickly | Scheduled backups with retention |
| Failover | Maintain service continuity | Redundant infrastructure |
| Testing | Validate preparedness | Drills and recovery simulations |
11. Compliance and Certifications
We align our security practices with applicable legal, regulatory, and industry guidance where practical and relevant.
11.1. Regulatory Compliance
Our approach reflects applicable legal obligations related to privacy, data protection, records handling, and secure processing.
11.2. Industry Certifications
We pursue relevant certifications and independent assurance activities where appropriate to strengthen trust and demonstrate maturity.
12. User Security Responsibilities
Users of our services share responsibility for protecting access credentials, sensitive information, and the integrity of the systems they use.
12.1. Password Management
Strong passwords, password rotation where required, and careful sharing practices help reduce the risk of account compromise.
12.2. Reporting Security Incidents
Users should report suspicious activity or security concerns immediately so that they can be investigated and contained.
12.3. Safe Use of Services and Data
Users are expected to use services safely, avoid unauthorized downloads, and protect sensitive information from exposure.
- Do not share credentials with unauthorized individuals.
- Use approved devices and networks where possible.
- Report any suspected compromise immediately.
13. Updates to This Policy
This policy may be updated periodically to reflect changes in technology, operating environment, or compliance obligations.
13.1. Policy Review Schedule
We review our security policy on a regular basis and after major changes to systems, services, or legal requirements.
13.2. Communication of Changes
Material changes to the policy will be communicated through appropriate channels so that stakeholders remain informed.
14. Contact Information
If you have concerns about security, need to report a vulnerability, or want additional information, please contact us using the details provided on our website.
14.1. Security Team Contact
Our security team can assist with questions related to controls, incidents, and service security practices.
14.2. Reporting Vulnerabilities
Responsible disclosure is welcomed. Please provide sufficient detail so that we can investigate and evaluate the issue appropriately.