1. Purpose and scope
This policy establishes the approach used by Eatwell Tech Solutions to protect the confidentiality, integrity and availability of ClassControl information and systems.
2. Governance
Security responsibilities are assigned to authorised personnel. Risks are reviewed when significant features, suppliers or infrastructure change.
3. Access control
Access follows least-privilege and need-to-know principles. Administrative functions are role restricted, and production access is limited to authorised personnel.
4. Cryptography
Approved modern cryptographic mechanisms are used for transport and protected application data. Key material is separated from public application code and must be backed up securely where recovery is required.
5. Secure development
Security is considered during design, implementation, testing and deployment. Prepared statements, output escaping, CSRF protection, validation and authentication checks are used where applicable.
6. Operational security
Systems are maintained, errors are logged without intentionally recording secrets, and access or configuration changes are controlled. Backups and recovery arrangements depend on the active hosting configuration and customer plan.
7. Incident management
Suspected incidents are assessed, contained and investigated. Customers and regulators are notified where required by applicable law and contractual obligations.
8. Review
This policy is reviewed when material platform, legal or risk changes occur and at appropriate intervals.