Security Policy
Last Updated: January 4, 2024
Strud Pex is committed to protecting the security of our platform, its users, and the data entrusted to us. This Security Policy describes the measures we take to safeguard information, the responsibilities of users, and the procedures we follow when responding to security incidents. By using our platform at strudpex.com, you acknowledge and agree to the practices described in this document.
1. Scope
This policy applies to all systems, services, and infrastructure operated by Strud Pex, including the strudpex.com website, associated web applications, databases, internal tools, and third-party integrations used to deliver our online learning platform. It applies to all users, staff members, contractors, and partners who interact with our systems in any capacity.
2. Data Protection Principles
We apply the following core principles when handling user data and platform information:
- Confidentiality: Access to sensitive data is restricted to authorized individuals only, based on the principle of least privilege.
- Integrity: We take measures to ensure that data is accurate, complete, and protected from unauthorized modification.
- Availability: We work to ensure that our platform and its data remain accessible to authorized users when needed.
- Accountability: Actions taken within our systems are logged and attributable to responsible parties.
3. Infrastructure Security
3.1 Hosting and Network
Our platform is hosted on infrastructure that employs industry-standard security controls. Network-level protections include firewalls, traffic filtering, and access controls to prevent unauthorized connections. We regularly review and update our infrastructure configuration to address emerging vulnerabilities.
3.2 Encryption
All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS). Sensitive data stored within our systems is encrypted at rest using recognized encryption standards. Encryption keys are managed securely and rotated on a defined schedule.
3.3 Access Controls
Access to internal systems and administrative interfaces is restricted to authorized personnel only. We enforce strong authentication requirements for staff accounts, including multi-factor authentication where applicable. Access rights are reviewed periodically and revoked promptly upon role changes or departure.
3.4 Vulnerability Management
We conduct regular vulnerability assessments of our systems and applications. Identified vulnerabilities are prioritized and remediated based on their severity and potential impact. We apply security patches to operating systems, software dependencies, and third-party components in a timely manner.
4. Application Security
4.1 Secure Development Practices
Our development team follows secure coding guidelines throughout the software development lifecycle. Code changes undergo review processes designed to identify security weaknesses before deployment. We apply input validation, output encoding, and other controls to reduce common application-level risks.
4.2 Authentication and Session Management
User accounts are protected by password requirements that enforce minimum complexity standards. Session tokens are generated securely, transmitted only over encrypted connections, and invalidated upon logout or after a defined period of inactivity. We implement protections against brute-force login attempts.
4.3 Data Isolation
User data is logically separated within our systems to prevent unauthorized access across accounts. Our architecture is designed so that one user's data cannot be accessed, modified, or viewed by another user without explicit authorization.
5. Third-Party Services
We use third-party services and integrations to support platform functionality. Before engaging third-party providers, we assess their security posture and require that they maintain appropriate security standards. We limit the data shared with third parties to what is necessary for the specific service being provided. We do not sell user data to any third party.
6. User Responsibilities
Users of the Strud Pex platform share responsibility for maintaining security. We ask all users to:
- Create strong, unique passwords for their accounts and keep them confidential.
- Refrain from sharing account credentials with other individuals.
- Log out of their accounts when using shared or public devices.
- Report any suspicious activity, unauthorized access, or security concerns to us promptly.
- Keep their contact information and account details accurate and up to date.
- Avoid attempting to probe, scan, or test the security of our platform without prior written authorization.
7. Prohibited Activities
The following activities are strictly prohibited on or against our platform:
- Attempting to gain unauthorized access to any account, system, or data.
- Introducing malicious code, malware, or exploits into our systems.
- Interfering with the availability or performance of the platform through denial-of-service attacks or similar means.
- Intercepting or monitoring communications without authorization.
- Circumventing authentication, encryption, or access control mechanisms.
- Harvesting or scraping user data without explicit permission.
Violations may result in immediate account suspension, termination of access, and referral to appropriate authorities where warranted.
8. Incident Response
8.1 Detection and Containment
We maintain monitoring systems designed to detect unusual activity, unauthorized access attempts, and potential security incidents. When a potential incident is identified, our team initiates a response process to assess, contain, and investigate the situation as quickly as possible.
8.2 Notification
In the event of a confirmed security incident that affects user data, we will notify affected users in a timely manner through available contact channels. Notifications will include a description of what occurred, the type of data involved, and the steps we are taking in response. We will also take any additional notification steps required by applicable obligations.
8.3 Post-Incident Review
Following a security incident, we conduct a review to identify root causes, evaluate the effectiveness of our response, and implement improvements to prevent recurrence. Lessons learned are incorporated into our ongoing security practices.
9. Physical Security
Access to physical locations where our systems and data are processed or stored is controlled and restricted to authorized personnel. We rely on data center providers that maintain physical security controls including access logging, surveillance, and environmental protections.
10. Employee and Contractor Security
All staff members and contractors with access to our systems are subject to security awareness requirements. Personnel are informed of their responsibilities regarding data protection and acceptable use of company systems. Access granted to employees and contractors is limited to what is required for their specific role and is revoked when no longer necessary.
11. Backup and Recovery
We maintain regular backups of critical platform data to support recovery in the event of data loss, corruption, or system failure. Backup processes are tested periodically to verify that data can be restored reliably. Backup data is protected with the same security controls applied to primary data.
12. Security Audits and Reviews
We conduct periodic internal reviews of our security controls, policies, and procedures. Where appropriate, we engage qualified external parties to perform independent assessments of our security posture. Findings from audits and reviews are addressed according to their severity and potential impact on the platform and its users.
13. Responsible Disclosure
If you discover a potential security vulnerability in our platform, we encourage you to report it to us responsibly before disclosing it publicly. Please contact us at info@strudpex.com with a description of the issue, steps to reproduce it, and any relevant technical details. We will acknowledge receipt of your report and work to investigate and address valid findings. We ask that you refrain from exploiting the vulnerability or disclosing it to others while we review and respond to your report.
14. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or obligations. When we make material changes, we will update the date at the top of this document and, where appropriate, notify users through platform communications or email. Continued use of our platform following an update constitutes acceptance of the revised policy. We encourage you to review this policy periodically.
15. Contact Us
If you have questions, concerns, or requests related to this Security Policy or our security practices, please contact us using the information below:
Strud Pex
Vidrodzhennya Ave, 22в, Lutsk, Volyn Oblast, Ukraine, 43000
Email: info@strudpex.com
Phone: +380633930958
Website: strudpex.com