Cybersecurity Policy

Last updated: September 3, 2026

1. Purpose and Scope

This Cybersecurity Policy sets requirements for protecting our services, systems, and information from unauthorized access, alteration, disclosure, disruption, or destruction. It applies to Stratifyre personnel, contractors, systems, and applications that process Stratifyre information. Requirements for service providers are addressed through provider assessment and applicable agreements.

The operational requirements below describe expected practices; they are not an attestation that every control has been implemented or independently verified in every environment. Specific application controls are described where relevant. Stratifyre management is responsible for assigning control owners and reviewing this policy at least annually and after material changes or incidents. Exceptions must have a documented risk assessment, management approval, an owner, mitigating safeguards, and a review or expiry date.

This policy supplements our Privacy Policy andTerms of Service. It does not change the purposes for which we collect or share personal information, override applicable law or written agreements, or create an uptime or recovery-time guarantee.

2. Data Classification and Handling

Information must be classified according to its sensitivity and the impact that unauthorized access, use, disclosure, modification, or loss could have:

Collection, retention, and disposal must follow our Privacy Policy, including retention needed for legal obligations, billing records, dispute resolution, and enforcement of agreements. Information must be securely deleted or de-identified when those purposes no longer require it. Restricted information must not be placed in source code, tickets, public repositories, or application logs. Copies, exports, and backups must receive protections appropriate to the highest classification they contain. Production data must not be used in development or testing unless authorized and protected.

3. Access Control and Privileged Access Management

Access must be limited to the permissions needed for an approved role or task. Personnel and system owners must ensure that:

Stratifyre provides optional authenticator-app two-factor authentication for web accounts. Administrative support impersonation sessions have an absolute time limit and audit records identifying the administrator and target account.

Personnel must protect authentication factors, use approved devices and software, lock unattended devices, and report suspected credential compromise promptly. Stratifyre may suspend sessions, rotate credentials, or restrict access when a security risk is identified.

4. Encryption of Data at Rest and in Transit

Customer-facing connections must use HTTPS with Transport Layer Security (TLS). Connections between services and to providers that carry Confidential or Restricted information must also use encrypted transport with certificate validation. System owners must document and address any gaps in coverage.

The application encrypts stored broker credentials and two-factor authentication secrets using AES-256-GCM authenticated encryption with per-user derived keys. Master encryption keys are supplied separately from the encrypted database records. This application-level protection does not by itself establish encryption of every database, disk, export, or backup.

System owners must provide encryption at rest for Confidential and Restricted information, including backups and exports, and document the scope of that protection. Passwords must be protected using salted, one-way password hashing. Encryption keys must have restricted access, secure recovery arrangements, and procedures for rotation or revocation following suspected compromise. Plaintext secrets must be limited to authorized operations and must not be written to logs or returned through ordinary account-information interfaces.

5. Vulnerability and Patch Management

System owners must identify and track security weaknesses in applications, dependencies, infrastructure, and configuration. They must maintain an inventory of supported components, review relevant security advisories and reports, and select vulnerability checks appropriate to the system. Development checks include automated secret scanning and software validation; these checks do not replace vulnerability assessment of deployed systems.

Each finding must have an owner, a remediation deadline based on severity, exploitability, exposure, and impact, and a record of resolution. Critical or actively exploited issues require prompt assessment for emergency patching, isolation, or other containment. Patches must be tested as appropriate to the risk, deployed through the change process, and checked for effectiveness. Delayed remediation requires documented mitigating safeguards and an approved, time-limited exception.

Unsupported components must be upgraded, replaced, or covered by an approved exception. Security findings must be handled as confidential information and shared only with authorized recipients involved in response or remediation.

6. Security Monitoring and Secure Development

System owners must select security events to log and review, establish escalation paths for suspicious activity, and protect audit records against unauthorized access or alteration. Logs must exclude credentials and limit personal information to what is needed for operation and investigation.

Software and infrastructure changes must receive review and validation appropriate to their security impact before release. Production access and credentials must be separated from development and test access. Personnel must receive security guidance relevant to their responsibilities.

7. Incident Response

Suspected or confirmed security incidents must be escalated to the responsible Stratifyre personnel. Management must assign an incident lead to coordinate:

If an incident affects customer information, we will assess the incident and provide notices to affected customers, authorities, and other required parties within the timeframes and through the channels required by applicable law or contractual commitments. Investigation and recovery must preserve relevant evidence and protect the confidentiality of incident records.

8. Disaster Recovery and Business Continuity

System owners must document backup and recovery procedures for critical systems, including responsible personnel, dependencies, backup frequency and retention, and restoration steps. Plans must address outages, data corruption, infrastructure loss, and security incidents. Recovery copies must be protected from unauthorized access, modification, and deletion, with separation from production failures and access controls appropriate to their classification.

Owners must set recovery priorities, target restoration times, and acceptable data-loss windows for each critical system. Restoration exercises must be scheduled according to risk and after material changes, with results and corrective actions recorded. Restored systems must be checked for data integrity and security before normal operation resumes. These are planning requirements; this policy does not promise a specific recovery time or backup frequency.

9. Physical Security

Physical controls apply to company-managed hardware, personnel workspaces, and third-party hosting facilities. Access to company-managed equipment must be limited to authorized personnel; visitors must be authorized and supervised. System owners must assess protection against theft, power loss, fire, and other environmental hazards. For provider-operated facilities, the responsible owner must assess the provider's physical and environmental safeguards and document the division of responsibilities.

Stratifyre personnel must secure company devices and work areas, prevent unauthorized viewing or removal of information, and report lost, stolen, or compromised equipment promptly. Storage media must be securely erased or destroyed before disposal or reuse.

10. Third-Party Providers

Responsible owners must assess providers that process or support access to Stratifyre information based on the service and information involved. Applicable agreements must address confidentiality, security responsibilities, access limitations, incident notification, and return or disposal of data. Use of a provider does not remove Stratifyre's obligations under applicable law or its agreements with customers.

11. Customer Responsibilities

Customers are responsible for protecting their accounts, devices, and third-party credentials. Customers should use a unique, strong password, enable two-factor authentication, review connected applications and scopes, avoid sharing credentials, keep devices and browsers updated, and promptly revoke or rotate credentials that may have been exposed. Customers should contact Stratifyre promptly if they suspect unauthorized account activity or access to their information.

12. Reporting Security Issues

To report a suspected vulnerability, account compromise, privacy or security incident, or other security concern, email[email protected] with the subject "Security report". Include a description, the affected service, and a way to contact you. Do not send passwords, API keys, private keys, customer data, or sensitive attachments; request a suitable transfer method if evidence is needed. Please do not post security reports in public community channels. Privacy questions may also be sent to[email protected].

13. Changes to This Policy

We may update this Cybersecurity Policy as our services, safeguards, or legal obligations change. We will post the revised policy on this page and update its revision date. Material changes may also be communicated through the Stratifyre service or by email where appropriate.