From infrastructure design to daily operations, security is embedded at every layer of how we work — not bolted on after the fact.
Every access request is verified regardless of origin. No implicit trust — users, devices and services authenticate and authorise at every layer.
Data in transit is protected with TLS 1.2+. Data at rest is encrypted using AES-256. Secrets are managed via dedicated vaulting solutions.
Our NOC operates around the clock, correlating alerts from SIEM, IDS/IPS and endpoint telemetry to detect and respond to threats before they escalate.
Critical CVEs are remediated within 72 hours. Monthly patch cycles for all other vulnerabilities, with full audit trails and rollback procedures.
Automated backups, tested failover procedures and documented recovery playbooks. RPO and RTO commitments are contractual, not aspirational.
Role-based access control (RBAC) with least-privilege principles. MFA enforced for all administrative access. Quarterly access reviews and offboarding procedures.
We take security reports seriously and appreciate the work of researchers who help us keep our systems safe. If you believe you have found a security vulnerability in our systems or website, please contact us privately before disclosing it publicly.
We commit to:
Please do not access, modify or delete data that does not belong to you, and do not disrupt live services during your research.
🔒 security@sepacyber.com