Security Policy
Last Updated: July 6, 2024
Dealquora is committed to protecting the security of information processed through its platform. This Security Policy describes the technical and organisational measures we apply to safeguard data and maintain the integrity, availability, and confidentiality of our services.
1. Scope
This policy applies to all systems, infrastructure, personnel, and third-party integrations involved in the operation of Dealquora's online platform and associated services. It covers all data processed on behalf of users, participants, and clients.
2. Information Security Principles
Our security programme is built on three foundational principles:
- Confidentiality: Information is accessible only to those authorised to access it.
- Integrity: Data is accurate, complete, and protected against unauthorised modification.
- Availability: Systems and data are accessible to authorised users when required.
3. Data Transmission Security
All data transmitted between users and our platform is encrypted in transit using industry-standard Transport Layer Security (TLS). Unencrypted connections are not permitted for any service endpoint that handles personal or session data.
4. Data Storage Security
Data stored within our systems is protected through the following measures:
- Encryption of sensitive data at rest using accepted cryptographic standards
- Access controls limiting data access to authorised personnel only
- Logical separation of data environments for production, staging, and development
- Regular integrity checks and audit logging of data access events
5. Access Control
5.1 User Access
User accounts are protected by credential-based authentication. Users are responsible for maintaining the confidentiality of their login credentials. We support session management controls including automatic session expiry after periods of inactivity.
5.2 Administrative Access
Internal access to production systems is restricted to authorised personnel on a need-to-know basis. Administrative access is subject to multi-factor authentication and is logged for audit purposes. Privileges are reviewed periodically and revoked upon role change or departure.
5.3 Third-Party Access
Where third-party service providers require access to systems or data, such access is governed by contractual obligations, limited in scope, and subject to the same security standards applied internally.
6. Network and Infrastructure Security
- Firewalls and network segmentation are used to restrict traffic between system components
- Intrusion detection mechanisms monitor for anomalous activity
- Infrastructure is hosted with providers that maintain recognised security certifications
- Unnecessary services and ports are disabled by default
7. Application Security
Security considerations are integrated into our development lifecycle. Measures include:
- Code review processes that incorporate security evaluation
- Input validation and output encoding to mitigate common web vulnerabilities
- Dependency management and timely application of security patches
- Regular testing of application components for known vulnerability classes
8. Vulnerability Management
We maintain an ongoing programme to identify, assess, and remediate security vulnerabilities. This includes monitoring of security advisories relevant to our technology stack and prompt application of patches to address identified risks. Critical vulnerabilities are prioritised for immediate remediation.
9. Security Monitoring and Logging
System and application events are logged to support security monitoring, incident detection, and forensic investigation. Logs are retained for a defined period and protected against unauthorised modification. Automated alerting is in place for events that indicate potential security incidents.
10. Incident Response
We maintain an incident response process to address security events in a timely and structured manner. Upon detection of a security incident, our response includes:
- Containment of the incident to limit impact
- Investigation to determine scope and root cause
- Remediation of the underlying issue
- Notification to affected parties where required
- Post-incident review to improve future response
Affected users will be notified of incidents that materially affect their data in accordance with our Privacy Policy and applicable obligations.
11. Business Continuity and Availability
We maintain backup procedures to ensure data can be recovered in the event of system failure or data loss. Backups are performed regularly, stored securely, and tested periodically to verify recoverability. Our infrastructure is designed with redundancy to support service continuity.
12. Personnel Security
Staff with access to systems or data are subject to security awareness training. Security responsibilities are communicated as part of onboarding and reinforced through ongoing guidance. Access rights are managed throughout the employment lifecycle and promptly revoked upon termination.
13. Physical Security
Our services are delivered through cloud infrastructure hosted in facilities that maintain physical access controls, environmental protections, and operational security measures appropriate for data centre environments.
14. Third-Party and Supply Chain Security
We evaluate the security posture of third-party providers before engagement and on an ongoing basis. Providers are required to maintain security standards consistent with this policy. Data processing agreements are established with providers who handle personal data on our behalf.
15. Responsible Disclosure
If you discover a potential security vulnerability in our platform or services, we encourage responsible disclosure. Please report findings to us at support@dealquora.info with sufficient detail to allow us to assess and reproduce the issue. We will acknowledge receipt and work to address confirmed vulnerabilities promptly. We ask that you refrain from exploiting any vulnerability or disclosing it publicly before we have had reasonable opportunity to respond.
16. Policy Review
This Security Policy is reviewed at least annually and updated as necessary to reflect changes in our systems, practices, or the threat environment. Continued use of our services following any update constitutes acceptance of the revised policy.
17. Contact
For questions or concerns regarding this Security Policy, please contact us:
Sturt St, Ballarat Central VIC 3350, Australia
Email: support@dealquora.info
Phone: +61 2 9838 4415