1. Security Principles
Security at altifly systems is approached as a continuous risk management process. We apply principles of least privilege, defense in depth, and proportionality to protect systems and data against unauthorized access, loss, or misuse.
2. Governance and Responsibility
Responsibility for information security rests with senior technical leadership. Security considerations are integrated into system design, development, and operational processes.
3. Infrastructure Security
Our services are hosted on professional cloud infrastructure within the European Union. Measures are implemented to protect infrastructure against unauthorized access, including network segmentation, firewalls, and secure configuration practices.
4. Application Security
Applications are designed following secure development practices. Access-controlled routes, input validation, and authentication mechanisms are used to reduce the risk of common vulnerabilities.
5. Data Protection and Encryption
Personal data processed through the Services is protected using appropriate technical measures, including encryption of stored data where relevant and secure transport mechanisms for data in transit.
6. Access Control
Access to systems and data is restricted to authorized personnel based on role and necessity. Administrative access is limited and reviewed periodically.
7. Monitoring and Logging
Logging and monitoring mechanisms are used to detect operational issues and potential security events. Logs are protected against unauthorized access and retained only as long as necessary.
8. Incident Response
We maintain procedures to respond to security incidents, including assessment, mitigation, and notification where required by applicable law.
9. Third-Party Services
Where third-party service providers are used, they are selected based on their ability to meet appropriate security and data protection standards. Access is limited to what is necessary for service provision.
10. Responsible Disclosure
We encourage responsible disclosure of potential security vulnerabilities. If you believe you have identified a security issue, please report it to [email protected].
11. Limitations
While we take reasonable measures to protect our systems and data, no system can be guaranteed to be completely secure. This page does not constitute a contractual guarantee or warranty regarding security.
12. Contact
For security-related inquiries, contact [email protected].