Security Policy
Last Updated: January 16, 2026
Introduction
Tortexio is committed to protecting the security and integrity of your information. This Security Policy outlines the measures we implement to safeguard data collected through our platform and services.
Information Security Framework
We maintain a comprehensive information security program designed to protect against unauthorized access, disclosure, alteration, or destruction of data. Our security framework is based on industry-recognized standards and best practices.
Security Principles
- Confidentiality: ensuring information is accessible only to authorized individuals
- Integrity: maintaining accuracy and completeness of data
- Availability: ensuring authorized users have access when needed
- Accountability: tracking and logging security-relevant activities
Technical Security Measures
Data Encryption
We employ encryption technologies to protect data both in transit and at rest:
- Transport Layer Security for all data transmitted over networks
- Encryption of sensitive data stored in databases
- Secure protocols for all external communications
- Encrypted backup storage systems
Access Controls
Access to systems and data is restricted through multiple layers of security:
- Role-based access control limiting permissions to necessary functions
- Multi-factor authentication for administrative access
- Regular review and update of access privileges
- Immediate revocation of access upon termination of authorization
- Strong password policies and enforcement
Network Security
Our network infrastructure incorporates protective measures including:
- Firewall protection on all network boundaries
- Intrusion detection and prevention systems
- Regular security patches and updates
- Network segmentation to isolate sensitive systems
- Continuous monitoring for suspicious activity
Application Security
We implement secure development practices throughout the software lifecycle:
- Security testing during development and deployment
- Code reviews focused on security vulnerabilities
- Regular vulnerability assessments and penetration testing
- Secure coding standards and guidelines
- Third-party security audits
Organizational Security Measures
Personnel Security
We ensure our team members understand and follow security protocols:
- Background verification for personnel with access to sensitive data
- Security awareness training for all employees
- Confidentiality agreements with staff and contractors
- Clear security roles and responsibilities
- Regular security education and updates
Vendor Management
Third-party service providers are evaluated for security compliance:
- Security assessments before vendor engagement
- Contractual security requirements and obligations
- Regular review of vendor security practices
- Data processing agreements where applicable
Physical Security
Physical access to facilities and equipment is controlled through:
- Restricted access to data centers and server rooms
- Surveillance systems in sensitive areas
- Visitor logging and escort procedures
- Secure disposal of physical media containing data
Data Protection Practices
Data Minimization
We collect and retain only the data necessary for legitimate purposes and delete information when no longer needed.
Data Backup and Recovery
Regular backups are performed to ensure data availability and business continuity:
- Automated backup procedures on defined schedules
- Encrypted backup storage in secure locations
- Regular testing of restoration procedures
- Disaster recovery and business continuity plans
Data Retention and Disposal
We maintain clear policies for data retention and secure disposal:
- Defined retention periods based on legal and business requirements
- Secure deletion methods for digital data
- Physical destruction of hardware containing sensitive information
- Documentation of disposal activities
Incident Response
Security Incident Management
We maintain procedures to detect, respond to, and recover from security incidents:
- Incident response team with defined roles
- Documented incident response procedures
- Logging and monitoring systems for early detection
- Incident classification and escalation protocols
- Post-incident analysis and improvement
Breach Notification
In the event of a security breach affecting personal information, we will:
- Investigate the incident promptly and thoroughly
- Notify affected individuals without undue delay
- Inform relevant authorities as required by law
- Provide information about the nature of the breach and mitigation steps
- Implement measures to prevent recurrence
Compliance and Auditing
Security Assessments
We regularly evaluate our security posture through:
- Internal security audits and reviews
- External security assessments by qualified professionals
- Vulnerability scanning and penetration testing
- Compliance audits against applicable standards
Continuous Improvement
Our security program evolves to address emerging threats and technologies:
- Regular review and update of security policies
- Monitoring of security trends and threat intelligence
- Implementation of new security technologies and practices
- Incorporation of lessons learned from incidents and assessments
User Responsibilities
Security is a shared responsibility. Users are expected to:
- Maintain confidentiality of account credentials
- Use strong, unique passwords for their accounts
- Enable multi-factor authentication when available
- Report suspicious activity or security concerns promptly
- Keep contact information current for security notifications
- Log out of accounts when using shared devices
- Avoid sharing account access with unauthorized individuals
Limitations
While we implement robust security measures, no system can guarantee absolute security. We cannot ensure or warrant complete security of information transmitted to or stored by our services. Users acknowledge that they provide information at their own risk.
Third-Party Services
Our platform may integrate with or link to third-party services. This Security Policy applies only to our services. We are not responsible for the security practices of external services and encourage users to review their security policies.
Policy Updates
We may update this Security Policy periodically to reflect changes in our practices or legal requirements. Material changes will be communicated through appropriate channels. Continued use of our services after updates constitutes acceptance of the revised policy.
Contact Information
For questions, concerns, or to report security issues related to this Security Policy, please contact us:
- Email: contact@tortexio.com
- Phone: +380800502500
- Address: Pasichna St, 68, Lviv, Lviv Oblast, Ukraine, 79000
Effective Date: January 16, 2026
This Security Policy is maintained by Tortexio and applies to all users of our platform and services.