← Back

Security Policy

Last updated: July 4, 2026

1. Introduction

Sellestic is committed to maintaining the confidentiality, integrity, and availability of all information assets. This policy applies to all systems we operate, all customer data we process, and all personnel who support our service.

2. Governance and Responsibilities

We maintain an information security program with designated owners accountable for security controls. All team members must adhere to this policy and acknowledge material updates as part of their responsibilities.

3. Risk Management

Security and privacy risks are evaluated on an ongoing basis with a focus on customer and business impact. Identified risks are documented, prioritised, and tracked through to closure to inform control updates and security investments.

4. Asset Management

Production infrastructure, source code repositories, and data stores are inventoried. Assets are classified by sensitivity with defined handling requirements for customer data, internal data, and public content.

5. Access Control

Access to systems and data is governed by the principle of least privilege. Provisioning, periodic reviews, and revocation follow documented procedures. Shared credentials are prohibited, and strong authentication is required where supported.

6. Secure Development and Change Management

All software development uses version control, code reviews, and automated checks. Production changes include testing, approval, and rollback planning. Sensitive secrets and credentials are managed through environment configuration — never stored in source code.

7. Data Protection

TLS encryption is required for all customer data in transit. Cloud providers handle storage-level encryption and physical security. Data collection and processing align with our Privacy Policy.

8. Operational Security and Monitoring

Production systems are continuously logged and monitored for anomalies. Security updates are applied in a timely manner to infrastructure and dependencies. Backups are scheduled regularly and periodically tested for successful restoration.

9. Incident Response

We maintain documented procedures covering detection, escalation, containment, eradication, and post-incident review. Customers will receive prompt notification when an incident materially affects their data or service availability.

10. Business Continuity and Disaster Recovery

Continuity plans address critical services and key supporting vendors. We conduct regular reviews and exercises to verify recovery objectives and ensure essential operations can be restored after disruptive events.

11. Supplier and Third-Party Management

Third-party services are evaluated for security posture before use and reviewed on an ongoing basis. Contracts with suppliers require confidentiality, availability, and privacy commitments. Supplier access is kept minimally scoped and regularly reviewed.

12. Personnel Security and Training

All team members complete confidentiality agreements and security and privacy training during onboarding. Responsibilities for handling customer data are clearly documented. Policy violations may result in disciplinary action up to and including termination.

13. Compliance and Policy Maintenance

This policy is reviewed at least annually and following any significant changes to the service or threat landscape. Privacy practices are detailed in our companion Privacy Policy.

14. Contact

To report a security concern or ask questions about this policy, contact us at hello@sellestic.com.