Security Policy

Last updated: December 21, 2024

Rimovlan is committed to protecting the security of our platform, our users, and the data entrusted to us. This Security Policy describes the measures we take to safeguard information, the responsibilities of users, and how we respond to security incidents.

1. Scope

This policy applies to all systems, services, and infrastructure operated by Rimovlan, including the website at vylycuy.com, associated learning platform services, and any data processed through these channels.

2. Data Protection and Encryption

2.1 Data in Transit

All data transmitted between users and our platform is encrypted using industry-standard Transport Layer Security (TLS). We enforce HTTPS across all pages and services to prevent interception of data in transit.

2.2 Data at Rest

Sensitive data stored on our systems is encrypted using strong encryption algorithms. Encryption keys are managed securely and are rotated on a regular basis.

2.3 Database Security

Our databases are not publicly accessible. Access is restricted to authorized internal services and personnel only, using network-level controls and authentication mechanisms.

3. Access Control

3.1 Principle of Least Privilege

Access to systems, infrastructure, and user data is granted on a need-to-know basis. Employees and contractors are provided only the minimum level of access required to perform their duties.

3.2 Authentication

Internal access to sensitive systems requires strong authentication, including multi-factor authentication where applicable. Default credentials are never used and are replaced immediately upon provisioning.

3.3 Access Reviews

Access rights are reviewed periodically. Access is revoked promptly when no longer required, including upon termination of employment or engagement.

4. Infrastructure Security

4.1 Hosting Environment

Our platform is hosted on reputable cloud infrastructure providers that maintain their own security certifications and compliance programs. We configure our environments according to security best practices.

4.2 Network Controls

We use firewalls, network segmentation, and intrusion detection mechanisms to monitor and control traffic to and from our systems.

4.3 Patch Management

Operating systems, software dependencies, and third-party libraries are kept up to date. Security patches are applied promptly following disclosure of vulnerabilities.

5. Application Security

5.1 Secure Development Practices

Our development team follows secure coding guidelines. Code changes undergo review before deployment to identify and address potential security issues.

5.2 Vulnerability Management

We conduct periodic security assessments of our application and infrastructure. Identified vulnerabilities are prioritized and remediated based on their severity.

5.3 Dependency Monitoring

Third-party dependencies used in our platform are monitored for known vulnerabilities. We update or replace affected dependencies as needed.

6. User Account Security

Users are responsible for maintaining the security of their own accounts. We recommend the following practices:

  • Use a strong, unique password for your Rimovlan account.
  • Do not share your login credentials with others.
  • Log out of your account when using shared or public devices.
  • Contact us immediately if you suspect unauthorized access to your account.

Passwords are stored using secure, one-way hashing algorithms. We do not store plaintext passwords.

7. Monitoring and Logging

We maintain logs of access and activity on our systems for security monitoring, incident investigation, and audit purposes. Logs are stored securely and retained for a defined period. Automated monitoring is in place to detect anomalous behavior and potential threats.

8. Incident Response

8.1 Detection and Response

We maintain an incident response process to detect, contain, and remediate security incidents in a timely manner. Our team is prepared to respond to incidents at any time.

8.2 Notification

In the event of a security incident that affects user data, we will notify affected users and relevant parties in accordance with applicable legal obligations and without undue delay.

8.3 Post-Incident Review

Following any significant security incident, we conduct a review to identify root causes and implement measures to prevent recurrence.

9. Third-Party Services

We may engage third-party service providers to support the operation of our platform. We assess the security practices of these providers before engagement and require them to maintain appropriate security standards. We do not permit third parties to use user data for purposes beyond those necessary to provide services to us.

10. Physical Security

Where we maintain physical infrastructure, access is restricted to authorized personnel. Our primary hosting relies on cloud infrastructure providers who maintain physical security controls at their facilities.

11. Employee Training and Awareness

All team members with access to systems or user data receive security awareness training. This includes guidance on recognizing phishing attempts, handling sensitive data, and following secure practices in day-to-day work.

12. Backups and Recovery

We maintain regular backups of critical data and system configurations. Backups are encrypted and stored securely. Recovery procedures are tested periodically to ensure they function as expected.

13. Responsible Disclosure

If you discover a potential security vulnerability in our platform, we ask that you report it to us responsibly before disclosing it publicly. Please contact us at help@vylycuy.com with details of the issue. We will investigate all reports and respond as quickly as possible. We ask that you do not exploit any vulnerability or access data beyond what is necessary to demonstrate the issue.

14. Changes to This Policy

We may update this Security Policy from time to time to reflect changes in our practices, technology, or legal requirements. The date at the top of this page indicates when the policy was last revised. Continued use of our platform following any update constitutes acceptance of the revised policy.

15. Contact

If you have any questions or concerns about this Security Policy or our security practices, please contact us: