Security Policy
Last updated: June 21, 2024
Pimnarek is committed to protecting the security of our platform, our clients, and the data entrusted to us. This Security Policy describes the technical and organizational measures we implement to safeguard information processed through our services.
1. Scope
This policy applies to all systems, infrastructure, and processes operated by Pimnarek in connection with the delivery of our online services, including our web platform, APIs, communication channels, and internal tooling used to support client engagements.
2. Data Protection Principles
We apply the following core principles to all data handling activities:
- Confidentiality: Access to data is restricted to authorized personnel with a legitimate need.
- Integrity: Data is protected against unauthorized modification or corruption.
- Availability: Systems are maintained to ensure reliable access for authorized users.
- Accountability: Actions affecting sensitive data are logged and attributable.
3. Infrastructure Security
3.1 Hosting and Environments
Our services are hosted on reputable cloud infrastructure providers that maintain industry-recognized security certifications. Production, staging, and development environments are logically separated to prevent cross-environment data exposure.
3.2 Network Security
We implement network-level controls including firewalls, private networking, and traffic filtering. Unnecessary ports and services are disabled by default. All inbound and outbound traffic is monitored for anomalies.
3.3 Encryption in Transit
All data transmitted between clients and our platform is encrypted using TLS 1.2 or higher. Unencrypted communication channels are not permitted for the transfer of sensitive information.
3.4 Encryption at Rest
Sensitive data stored on our systems is encrypted at rest using industry-standard encryption algorithms. Encryption keys are managed securely and rotated on a defined schedule.
4. Access Control
4.1 Principle of Least Privilege
Access to systems and data is granted based on the minimum level required to perform a specific function. Permissions are reviewed periodically and revoked promptly when no longer required.
4.2 Authentication
All internal systems require strong authentication. Where available, multi-factor authentication is enforced for access to production environments and administrative interfaces.
4.3 Credential Management
Credentials are never stored in plaintext. Passwords are hashed using strong, modern algorithms. API keys and secrets are stored in secure vaults and excluded from version control systems.
4.4 Third-Party Access
Any third-party vendors or contractors granted access to our systems are subject to the same access control standards and are bound by confidentiality obligations.
5. Application Security
5.1 Secure Development Practices
Security considerations are integrated throughout the software development lifecycle. Code changes undergo review prior to deployment. Known vulnerability patterns such as injection attacks, cross-site scripting, and insecure deserialization are actively mitigated.
5.2 Dependency Management
Third-party libraries and dependencies are monitored for known vulnerabilities. Updates and patches are applied in a timely manner based on risk severity.
5.3 Security Testing
We conduct periodic security assessments including vulnerability scanning and code review. Critical findings are remediated according to defined timelines based on severity classification.
6. Monitoring and Incident Response
6.1 Logging and Monitoring
System events, access attempts, and application activity are logged and retained for a defined period. Logs are protected against tampering and reviewed for indicators of unauthorized activity.
6.2 Incident Detection
Automated alerting is configured to detect anomalous behavior, unauthorized access attempts, and service disruptions. Alerts are routed to responsible personnel for timely review.
6.3 Incident Response
We maintain an incident response process that includes containment, investigation, remediation, and post-incident review. In the event of a confirmed security incident affecting client data, affected parties will be notified in accordance with applicable obligations and without undue delay.
7. Physical Security
Pimnarek operates as an online service without client-facing physical infrastructure. Our cloud service providers maintain physical security controls including restricted facility access, environmental controls, and surveillance at their data centers.
8. Business Continuity and Backup
Critical data is backed up on a regular schedule. Backups are encrypted and stored in geographically separate locations where applicable. Recovery procedures are tested periodically to verify data can be restored within acceptable timeframes.
9. Personnel Security
Team members with access to sensitive systems or client data are subject to confidentiality obligations. Security awareness is maintained through internal guidelines and periodic communication regarding current threats and safe practices. Access is revoked promptly upon termination of engagement.
10. Vulnerability Disclosure
If you believe you have identified a security vulnerability in our platform or services, we encourage responsible disclosure. Please report your findings to us at contact@pimnarek.com with sufficient detail to reproduce the issue. We will acknowledge receipt and work to investigate and remediate confirmed vulnerabilities in a timely manner. We ask that you do not publicly disclose findings until we have had a reasonable opportunity to respond.
11. Third-Party Services
Our platform may integrate with or rely upon third-party services. We evaluate third-party providers for security practices prior to integration and prefer providers that maintain recognized security standards. We are not responsible for the independent security practices of external services outside our control.
12. Policy Review and Updates
This Security Policy is reviewed periodically and updated to reflect changes in our technology, operations, or the threat landscape. The date at the top of this document indicates when the policy was last revised. Continued use of our services following an update constitutes acceptance of the revised policy.
13. Contact
For questions or concerns related to this Security Policy, please contact us:
Pimnarek
Anoshkina Ave, 61, Kamianske, Dnipropetrovsk Oblast, Ukraine, 51909
Email: contact@pimnarek.com
Phone: +380956188704