Security Policy
Last updated: November 27, 2025
redacpv is committed to maintaining the security, integrity, and confidentiality of all information processed through its platform at redacpv.com. This Security Policy describes the technical and organizational measures we apply to protect our systems and the data entrusted to us by our users.
1. Scope
This policy applies to all systems, services, infrastructure, and personnel associated with the operation of redacpv.com. It covers all data processed, stored, or transmitted through our platform, including user account information, session data, and communication records.
2. Data Protection Principles
We apply the following core principles when handling all data:
- Data is collected only to the extent necessary for the intended service function.
- Access to personal and sensitive data is restricted to authorized personnel only.
- Data is retained only for as long as operationally or legally required.
- All data handling practices are reviewed periodically to ensure ongoing appropriateness.
3. Infrastructure Security
3.1 Hosting and Network
Our platform is hosted on infrastructure that maintains physical and logical security controls. Network-level protections include firewalls, traffic filtering, and monitoring systems designed to detect and respond to anomalous activity.
3.2 Encryption in Transit
All data transmitted between users and our platform is encrypted using industry-standard TLS protocols. Unencrypted connections are not accepted by our services.
3.3 Encryption at Rest
Sensitive data stored within our systems is protected using encryption at rest. Storage systems containing personal or session-related data are not accessible without authenticated authorization.
4. Access Control
4.1 Internal Access
Access to production systems and user data is granted on a least-privilege basis. Each team member is provided only the level of access required to perform their designated responsibilities. Access rights are reviewed and adjusted when roles change.
4.2 Authentication
Internal administrative access requires strong authentication. Where supported, multi-factor authentication is enforced for access to sensitive systems and management interfaces.
4.3 Third-Party Access
Any third-party service provider granted access to our systems or data is required to operate under equivalent or greater security standards. Access is scoped, monitored, and revoked upon termination of the relationship.
5. Application Security
5.1 Secure Development Practices
Security considerations are integrated throughout our development lifecycle. Code changes are reviewed before deployment. Known vulnerability classes including injection attacks, authentication weaknesses, and insecure data exposure are addressed as part of standard development review.
5.2 Dependency Management
Third-party libraries and software dependencies used within our platform are monitored for known vulnerabilities. Updates and patches are applied in a timely manner based on risk assessment.
5.3 Input Validation
All user-supplied input is validated and sanitized before processing. Our application layer is designed to reject malformed or potentially harmful input at the point of entry.
6. Monitoring and Incident Response
6.1 System Monitoring
Our infrastructure and application layers are subject to continuous monitoring. Logs are collected and retained to support security review, anomaly detection, and incident investigation.
6.2 Incident Response
We maintain an internal incident response process to identify, contain, and remediate security events. In the event of a confirmed breach affecting user data, affected users will be notified in a timely manner in accordance with our obligations and the nature of the incident.
6.3 Post-Incident Review
Following any significant security event, a review is conducted to identify contributing factors and implement corrective measures to reduce the likelihood of recurrence.
7. Vulnerability Disclosure
If you believe you have identified a security vulnerability affecting our platform, we encourage responsible disclosure. Please contact us directly at contact@redacpv.com with a description of the issue. We will acknowledge receipt, investigate the report, and communicate our findings and any remediation steps taken.
We ask that you do not publicly disclose potential vulnerabilities before we have had a reasonable opportunity to assess and address them.
8. User Responsibilities
The security of your account is a shared responsibility. We ask that users:
- Use a strong, unique password for their account and do not share credentials with others.
- Log out of sessions when using shared or public devices.
- Report any suspicious activity on their account to us promptly.
- Keep contact information current so that security notifications can be delivered effectively.
9. Data Backup and Recovery
Critical data is backed up on a regular schedule. Backup integrity is verified periodically. Recovery procedures are maintained to support restoration of service in the event of data loss or system failure.
10. Organizational Measures
Security awareness is maintained across our team through internal guidelines and role-appropriate training. Personnel with access to sensitive systems or data are made aware of their responsibilities under this policy. Confidentiality obligations apply to all team members and contractors.
11. Policy Review
This Security Policy is reviewed on a regular basis and updated as necessary to reflect changes in our technology, operations, or applicable standards. Continued use of our platform following any update constitutes acceptance of the revised policy.
12. Contact
For questions or concerns related to this Security Policy, please contact us:
| Channel | Details |
|---|---|
| contact@redacpv.com | |
| Phone | +20 100 580 3330 |
| Website | redacpv.com |