Security Policy
Last updated: August 24, 2024
Velmor Ona is committed to protecting the security of its platform, services, and the data entrusted to us by our users. This Security Policy describes the technical and organizational measures we apply to safeguard information processed through velmorona.com and all associated services.
1. Scope
This policy applies to all systems, networks, applications, and data assets operated by Velmor Ona, including the web platform, backend infrastructure, communication channels, and third-party integrations used to deliver our educational services.
2. Data Protection Principles
We follow industry-accepted principles when handling user data:
| Principle | Description |
|---|---|
| Confidentiality | Data is accessible only to authorized personnel and systems with a legitimate need. |
| Integrity | Data is protected against unauthorized modification or corruption. |
| Availability | Systems and data remain accessible to authorized users as expected. |
| Minimization | Only data necessary for the stated purpose is collected and retained. |
3. Infrastructure Security
3.1 Hosting and Network
Our services are hosted on infrastructure provided by reputable cloud service providers that maintain independent security certifications. Network access is restricted through firewalls, access control lists, and segmented environments. Production systems are isolated from development and staging environments.
3.2 Encryption in Transit
All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS 1.2 or higher). Unencrypted HTTP connections are redirected to HTTPS automatically. Secure communication protocols are enforced across all endpoints.
3.3 Encryption at Rest
Sensitive data stored on our servers is encrypted at rest using industry-standard encryption algorithms. Database backups are also encrypted and stored securely with restricted access.
4. Access Control
4.1 Internal Access
Access to production systems and user data is granted on a least-privilege basis. Only personnel who require access to perform their job functions are granted it. Access rights are reviewed periodically and revoked promptly upon role change or termination.
4.2 Authentication
Internal systems require strong authentication mechanisms. Multi-factor authentication (MFA) is enforced for access to critical infrastructure and administrative interfaces. Shared credentials are not permitted.
4.3 User Accounts
User accounts on the platform are protected by password requirements that enforce minimum complexity. Passwords are stored using one-way cryptographic hashing with salting. Users are encouraged to enable additional authentication measures where available.
5. Application Security
5.1 Secure Development
Security is integrated into our software development lifecycle. Code changes undergo review before deployment. We apply protections against common vulnerabilities including but not limited to SQL injection, cross-site scripting (XSS), cross-site request forgery (CSRF), and insecure direct object references.
5.2 Dependency Management
Third-party libraries and dependencies are monitored for known vulnerabilities. Updates and patches are applied in a timely manner following security advisories from relevant sources.
5.3 Security Testing
We conduct periodic security assessments of our platform, including vulnerability scanning and code-level reviews. Identified issues are prioritized and remediated according to their severity.
6. Monitoring and Logging
Our systems generate logs of significant security events including authentication attempts, access to sensitive data, and configuration changes. Logs are retained for a defined period and reviewed for anomalies. Automated alerting is in place for patterns indicative of potential security incidents.
7. Incident Response
We maintain an incident response process to identify, contain, investigate, and remediate security incidents. In the event of a confirmed breach affecting user data, we will notify affected users and relevant parties in accordance with our obligations and within a reasonable timeframe. Notifications will include the nature of the incident, data involved, and steps taken or recommended.
8. Third-Party Service Providers
We engage third-party vendors only when necessary to deliver our services. Vendors with access to user data are evaluated for their security practices prior to engagement and are required to maintain appropriate safeguards. Data processing agreements are established where applicable.
9. Physical Security
We do not operate our own data centers. Physical security of underlying infrastructure is the responsibility of our cloud hosting providers, who maintain physical access controls, environmental protections, and security certifications at their facilities.
10. Business Continuity and Backup
Critical data is backed up regularly. Backups are tested periodically to verify recoverability. We maintain continuity procedures to restore service availability in the event of significant disruption.
11. Employee Security Practices
All personnel with access to systems or user data receive security awareness guidance. Employees are required to follow internal security policies, use approved tools, and report suspected security issues through designated internal channels.
12. Vulnerability Disclosure
If you believe you have discovered a security vulnerability in our platform, we encourage responsible disclosure. Please contact us at contact@velmorona.com with a description of the issue. We will acknowledge receipt, investigate the report, and work to address confirmed vulnerabilities promptly. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to respond.
13. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technologies, or obligations. The date at the top of this page indicates when the policy was last revised. Continued use of our services following any update constitutes acceptance of the revised policy.
14. Contact
For questions or concerns regarding this Security Policy, please contact us: