HomeAbout Get started →
HomeSecurity

Security is our
operational baseline.

From infrastructure design to daily operations, security is embedded at every layer of how we work — not bolted on after the fact.

ISO 27001 Aligned
ISO 9001
ITIL v4
GDPR Compliant
SOC 2 Ready
DORA Aligned
Security pillars

How we protect your environment.

Zero-trust architecture

Every access request is verified regardless of origin. No implicit trust — users, devices and services authenticate and authorise at every layer.

Encryption everywhere

Data in transit is protected with TLS 1.2+. Data at rest is encrypted using AES-256. Secrets are managed via dedicated vaulting solutions.

24/7 threat monitoring

Our NOC operates around the clock, correlating alerts from SIEM, IDS/IPS and endpoint telemetry to detect and respond to threats before they escalate.

Proactive patch management

Critical CVEs are remediated within 72 hours. Monthly patch cycles for all other vulnerabilities, with full audit trails and rollback procedures.

Disaster recovery

Automated backups, tested failover procedures and documented recovery playbooks. RPO and RTO commitments are contractual, not aspirational.

Access control & IAM

Role-based access control (RBAC) with least-privilege principles. MFA enforced for all administrative access. Quarterly access reviews and offboarding procedures.

Operational security

Security built into every process.

Infrastructure

Network segmentation and firewall rules reviewed quarterly
Immutable infrastructure — servers are replaced, not patched in place
DDoS protection and WAF on all public-facing endpoints
Automated vulnerability scanning on every deployment
Centralised logging with 12-month retention and tamper detection

People & process

Background checks for all employees with system access
Annual security awareness training — mandatory for all staff
Incident response playbooks tested via tabletop exercises twice yearly
Change management board approval required for production changes
Formal supplier security assessment before any third-party onboarding
Responsible disclosure

Found a vulnerability?

Security disclosure policy

We take security reports seriously and appreciate the work of researchers who help us keep our systems safe. If you believe you have found a security vulnerability in our systems or website, please contact us privately before disclosing it publicly.

We commit to:

  • Acknowledge your report within 2 business days
  • Investigate and provide a resolution timeline within 10 business days
  • Not pursue legal action against good-faith security researchers
  • Credit you in our acknowledgements (if you wish)

Please do not access, modify or delete data that does not belong to you, and do not disrupt live services during your research.

🔒 security@sepacyber.com