Security

Information Security Policy

The security principles and organisational controls supporting ClassControl.

Effective: 18 July 2026 Last reviewed: 18 July 2026 Version: 1.0

1. Purpose and scope

This policy establishes the approach used by Eatwell Tech Solutions to protect the confidentiality, integrity and availability of ClassControl information and systems.

2. Governance

Security responsibilities are assigned to authorised personnel. Risks are reviewed when significant features, suppliers or infrastructure change.

3. Access control

Access follows least-privilege and need-to-know principles. Administrative functions are role restricted, and production access is limited to authorised personnel.

4. Cryptography

Approved modern cryptographic mechanisms are used for transport and protected application data. Key material is separated from public application code and must be backed up securely where recovery is required.

5. Secure development

Security is considered during design, implementation, testing and deployment. Prepared statements, output escaping, CSRF protection, validation and authentication checks are used where applicable.

6. Operational security

Systems are maintained, errors are logged without intentionally recording secrets, and access or configuration changes are controlled. Backups and recovery arrangements depend on the active hosting configuration and customer plan.

7. Incident management

Suspected incidents are assessed, contained and investigated. Customers and regulators are notified where required by applicable law and contractual obligations.

8. Review

This policy is reviewed when material platform, legal or risk changes occur and at appropriate intervals.