Security Policy

Last updated: 29 August 2024

Giligey is committed to protecting the security of its platform, user data, and the systems that support its services. This Security Policy describes the measures we take to safeguard information and outlines the responsibilities of both Giligey and its users in maintaining a secure environment.

1. Scope

This policy applies to all systems, services, infrastructure, and data managed or operated by Giligey, including the giligey.com platform and any associated applications or tools made available to users.

2. Data Protection Principles

We handle all data in accordance with the following core principles:

3. Technical Security Measures

3.1 Encryption

All data transmitted between users and our platform is encrypted using TLS (Transport Layer Security). Sensitive data stored within our systems is encrypted using strong, widely accepted cryptographic standards.

3.2 Access Controls

Access to internal systems and administrative interfaces is protected by:

3.3 Network Security

Our infrastructure is protected by firewalls, intrusion detection systems, and continuous network monitoring. Traffic is filtered and anomalous activity is flagged for investigation.

3.4 Vulnerability Management

We conduct regular security assessments, including automated vulnerability scanning and periodic penetration testing. Identified vulnerabilities are triaged and remediated according to their severity level.

3.5 Patch Management

Software dependencies, operating systems, and third-party components are monitored for known vulnerabilities. Critical patches are applied in a timely manner following a defined patch management process.

4. Organisational Security

4.1 Personnel

All staff with access to user data or internal systems are subject to background screening appropriate to their role. Personnel receive regular security awareness training covering topics such as phishing, social engineering, and safe data handling.

4.2 Confidentiality Obligations

All team members and contractors are bound by confidentiality agreements. Access to sensitive systems or data is granted only after formal onboarding and approval.

4.3 Third-Party Providers

We assess the security posture of third-party vendors and service providers before engagement. Contracts with third parties include appropriate data protection and security obligations. We review vendor security practices on an ongoing basis.

5. Incident Response

We maintain a documented incident response plan that covers detection, containment, investigation, and recovery. In the event of a confirmed security incident affecting user data:

To report a suspected security incident, contact us at contact@giligey.com .

6. Business Continuity and Disaster Recovery

We maintain backup procedures and disaster recovery plans to ensure service continuity in the event of system failure, data loss, or other disruptions. Backups are performed regularly and tested periodically to verify integrity and restorability.

7. Physical Security

Systems that host our platform and data are located in facilities with physical access controls, including restricted entry, surveillance, and environmental protections against fire, flooding, and power failure.

8. Secure Development

Security is integrated into our software development lifecycle. Our development practices include:

9. User Responsibilities

Users of the Giligey platform share responsibility for maintaining security. We ask that users:

10. Responsible Disclosure

If you discover a potential security vulnerability in our platform, we encourage responsible disclosure. Please report findings to contact@giligey.com with sufficient detail to allow us to reproduce and investigate the issue. We ask that you:

We will acknowledge receipt of your report and keep you informed of our progress.

11. Monitoring and Logging

We maintain logs of access and activity across our systems for security monitoring and audit purposes. Logs are retained for a defined period and protected against unauthorised access or modification. Automated alerts are configured to detect and notify of unusual activity patterns.

12. Compliance

Our security practices are designed to align with widely recognised security frameworks and standards. We review our controls regularly to ensure they remain effective and appropriate to the nature of our services and the data we process.

13. Policy Review

This Security Policy is reviewed at least annually and updated as necessary to reflect changes in our practices, technology, or applicable requirements. Continued use of our services following any update constitutes acceptance of the revised policy.

14. Contact

For questions or concerns regarding this Security Policy, please contact us: