Security Policy
Last updated: 29 August 2024
Giligey is committed to protecting the security of its platform, user data, and the systems that support its services. This Security Policy describes the measures we take to safeguard information and outlines the responsibilities of both Giligey and its users in maintaining a secure environment.
1. Scope
This policy applies to all systems, services, infrastructure, and data managed or operated by Giligey, including the giligey.com platform and any associated applications or tools made available to users.
2. Data Protection Principles
We handle all data in accordance with the following core principles:
- Data is collected only to the extent necessary for the delivery of our services.
- Access to sensitive data is restricted to authorised personnel on a need-to-know basis.
- Data is stored using industry-standard encryption techniques both at rest and in transit.
- Retention periods are defined and data is securely disposed of when no longer required.
3. Technical Security Measures
3.1 Encryption
All data transmitted between users and our platform is encrypted using TLS (Transport Layer Security). Sensitive data stored within our systems is encrypted using strong, widely accepted cryptographic standards.
3.2 Access Controls
Access to internal systems and administrative interfaces is protected by:
- Multi-factor authentication (MFA) for all personnel with system access.
- Role-based access control (RBAC) to limit permissions to those required for a given function.
- Regular review and revocation of access rights when no longer needed.
3.3 Network Security
Our infrastructure is protected by firewalls, intrusion detection systems, and continuous network monitoring. Traffic is filtered and anomalous activity is flagged for investigation.
3.4 Vulnerability Management
We conduct regular security assessments, including automated vulnerability scanning and periodic penetration testing. Identified vulnerabilities are triaged and remediated according to their severity level.
3.5 Patch Management
Software dependencies, operating systems, and third-party components are monitored for known vulnerabilities. Critical patches are applied in a timely manner following a defined patch management process.
4. Organisational Security
4.1 Personnel
All staff with access to user data or internal systems are subject to background screening appropriate to their role. Personnel receive regular security awareness training covering topics such as phishing, social engineering, and safe data handling.
4.2 Confidentiality Obligations
All team members and contractors are bound by confidentiality agreements. Access to sensitive systems or data is granted only after formal onboarding and approval.
4.3 Third-Party Providers
We assess the security posture of third-party vendors and service providers before engagement. Contracts with third parties include appropriate data protection and security obligations. We review vendor security practices on an ongoing basis.
5. Incident Response
We maintain a documented incident response plan that covers detection, containment, investigation, and recovery. In the event of a confirmed security incident affecting user data:
- Affected users will be notified without undue delay where required.
- The nature of the incident, data involved, and steps taken will be communicated clearly.
- A post-incident review will be conducted to prevent recurrence.
To report a suspected security incident, contact us at contact@giligey.com .
6. Business Continuity and Disaster Recovery
We maintain backup procedures and disaster recovery plans to ensure service continuity in the event of system failure, data loss, or other disruptions. Backups are performed regularly and tested periodically to verify integrity and restorability.
7. Physical Security
Systems that host our platform and data are located in facilities with physical access controls, including restricted entry, surveillance, and environmental protections against fire, flooding, and power failure.
8. Secure Development
Security is integrated into our software development lifecycle. Our development practices include:
- Code review processes that include security considerations.
- Testing environments that are isolated from production systems.
- Input validation and output encoding to prevent common vulnerabilities such as injection attacks.
- Adherence to recognised secure coding guidelines.
9. User Responsibilities
Users of the Giligey platform share responsibility for maintaining security. We ask that users:
- Choose strong, unique passwords and do not share account credentials.
- Enable any available account security features such as two-factor authentication.
- Log out of their accounts when using shared or public devices.
- Report any suspicious activity or potential security issues to us promptly.
- Keep their own devices and software up to date with security patches.
10. Responsible Disclosure
If you discover a potential security vulnerability in our platform, we encourage responsible disclosure. Please report findings to contact@giligey.com with sufficient detail to allow us to reproduce and investigate the issue. We ask that you:
- Do not exploit the vulnerability or access data beyond what is necessary to demonstrate the issue.
- Do not disclose the vulnerability publicly until we have had a reasonable opportunity to address it.
We will acknowledge receipt of your report and keep you informed of our progress.
11. Monitoring and Logging
We maintain logs of access and activity across our systems for security monitoring and audit purposes. Logs are retained for a defined period and protected against unauthorised access or modification. Automated alerts are configured to detect and notify of unusual activity patterns.
12. Compliance
Our security practices are designed to align with widely recognised security frameworks and standards. We review our controls regularly to ensure they remain effective and appropriate to the nature of our services and the data we process.
13. Policy Review
This Security Policy is reviewed at least annually and updated as necessary to reflect changes in our practices, technology, or applicable requirements. Continued use of our services following any update constitutes acceptance of the revised policy.
14. Contact
For questions or concerns regarding this Security Policy, please contact us:
- Giligey
- Douglas Rd, Ballinlough, Cork, T12 K6EK, Ireland
- Phone: +353 1 840 2194
- Email: contact@giligey.com