Data Security Policy

1. Security Controls

  • TLS in transit; provider encryption at rest; optional client-side encryption for sensitive media.
  • RBAC, least privilege, MFA for internal admins.
  • Secure SDLC, code reviews, secret scanning, dependency monitoring.

2. Infrastructure

  • Hardened managed services; network segmentation; WAF where applicable.
  • Regular backups with tested restore procedures.
  • Audit logs and access reviews.

3. Incident Response

  • Detection → Triage → Containment → Eradication → Recovery → Postmortem.
  • User notifications provided where legally required.

4. Data Retention & Backups

  • Operational backups stored encrypted; retention windows vary by dataset.
  • Users can request deletion; backups age out per schedule.

5. Contact

security@untitledneedleworks.com