Security Policy
Last updated: December 21, 2024
Rimovlan is committed to protecting the security of our platform, our users, and the data entrusted to us. This Security Policy describes the measures we take to safeguard information, the responsibilities of users, and how we respond to security incidents.
1. Scope
This policy applies to all systems, services, and infrastructure operated by Rimovlan, including the website at vylycuy.com, associated learning platform services, and any data processed through these channels.
2. Data Protection and Encryption
2.1 Data in Transit
All data transmitted between users and our platform is encrypted using industry-standard Transport Layer Security (TLS). We enforce HTTPS across all pages and services to prevent interception of data in transit.
2.2 Data at Rest
Sensitive data stored on our systems is encrypted using strong encryption algorithms. Encryption keys are managed securely and are rotated on a regular basis.
2.3 Database Security
Our databases are not publicly accessible. Access is restricted to authorized internal services and personnel only, using network-level controls and authentication mechanisms.
3. Access Control
3.1 Principle of Least Privilege
Access to systems, infrastructure, and user data is granted on a need-to-know basis. Employees and contractors are provided only the minimum level of access required to perform their duties.
3.2 Authentication
Internal access to sensitive systems requires strong authentication, including multi-factor authentication where applicable. Default credentials are never used and are replaced immediately upon provisioning.
3.3 Access Reviews
Access rights are reviewed periodically. Access is revoked promptly when no longer required, including upon termination of employment or engagement.
4. Infrastructure Security
4.1 Hosting Environment
Our platform is hosted on reputable cloud infrastructure providers that maintain their own security certifications and compliance programs. We configure our environments according to security best practices.
4.2 Network Controls
We use firewalls, network segmentation, and intrusion detection mechanisms to monitor and control traffic to and from our systems.
4.3 Patch Management
Operating systems, software dependencies, and third-party libraries are kept up to date. Security patches are applied promptly following disclosure of vulnerabilities.
5. Application Security
5.1 Secure Development Practices
Our development team follows secure coding guidelines. Code changes undergo review before deployment to identify and address potential security issues.
5.2 Vulnerability Management
We conduct periodic security assessments of our application and infrastructure. Identified vulnerabilities are prioritized and remediated based on their severity.
5.3 Dependency Monitoring
Third-party dependencies used in our platform are monitored for known vulnerabilities. We update or replace affected dependencies as needed.
6. User Account Security
Users are responsible for maintaining the security of their own accounts. We recommend the following practices:
- Use a strong, unique password for your Rimovlan account.
- Do not share your login credentials with others.
- Log out of your account when using shared or public devices.
- Contact us immediately if you suspect unauthorized access to your account.
Passwords are stored using secure, one-way hashing algorithms. We do not store plaintext passwords.
7. Monitoring and Logging
We maintain logs of access and activity on our systems for security monitoring, incident investigation, and audit purposes. Logs are stored securely and retained for a defined period. Automated monitoring is in place to detect anomalous behavior and potential threats.
8. Incident Response
8.1 Detection and Response
We maintain an incident response process to detect, contain, and remediate security incidents in a timely manner. Our team is prepared to respond to incidents at any time.
8.2 Notification
In the event of a security incident that affects user data, we will notify affected users and relevant parties in accordance with applicable legal obligations and without undue delay.
8.3 Post-Incident Review
Following any significant security incident, we conduct a review to identify root causes and implement measures to prevent recurrence.
9. Third-Party Services
We may engage third-party service providers to support the operation of our platform. We assess the security practices of these providers before engagement and require them to maintain appropriate security standards. We do not permit third parties to use user data for purposes beyond those necessary to provide services to us.
10. Physical Security
Where we maintain physical infrastructure, access is restricted to authorized personnel. Our primary hosting relies on cloud infrastructure providers who maintain physical security controls at their facilities.
11. Employee Training and Awareness
All team members with access to systems or user data receive security awareness training. This includes guidance on recognizing phishing attempts, handling sensitive data, and following secure practices in day-to-day work.
12. Backups and Recovery
We maintain regular backups of critical data and system configurations. Backups are encrypted and stored securely. Recovery procedures are tested periodically to ensure they function as expected.
13. Responsible Disclosure
If you discover a potential security vulnerability in our platform, we ask that you report it to us responsibly before disclosing it publicly. Please contact us at help@vylycuy.com with details of the issue. We will investigate all reports and respond as quickly as possible. We ask that you do not exploit any vulnerability or access data beyond what is necessary to demonstrate the issue.
14. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or legal requirements. The date at the top of this page indicates when the policy was last revised. Continued use of our platform following any update constitutes acceptance of the revised policy.
15. Contact
If you have any questions or concerns about this Security Policy or our security practices, please contact us:
- Email: help@vylycuy.com
- Phone: +353 65 905 8014
- WhatsApp: https://wa.me/353659058014
- Address: Castlebar St, Carrowbaun, Newport, Co. Mayo, F28 CY52, Ireland