1. Purpose
Anilocus Inc. is committed to protecting the confidentiality, integrity, and availability of its information systems, data, and intellectual property.
2. Information Security Principles
- Confidentiality: Information is accessible only to authorized individuals
- Integrity: Information is protected from unauthorized modification
- Availability: Information and systems are accessible when needed
- Accountability: Access is logged, monitored, and auditable
- Least Privilege: Users are granted minimum necessary access
3. Access Control
Access is controlled through unique user accounts, strong password requirements, multi-factor authentication for privileged access, role-based access controls, and regular access reviews.
4. Data Protection
Data in transit is encrypted using TLS/SSL. Data at rest is encrypted where feasible. Data is securely deleted when no longer needed. Critical data is backed up regularly.
5. Network Security
We maintain firewalls, intrusion detection/prevention systems, network segmentation, regular vulnerability scanning, and penetration testing.
6. Third-Party Security
Third-party service providers must maintain appropriate security controls and execute data processing agreements.
7. Incident Response
We maintain an incident response plan including detection, reporting, response, communication, and post-incident analysis procedures.
8. Reporting Security Concerns
To report a security vulnerability or concern, contact us.
