1.Purpose and scope
1.1
This Policy sets out the principles and the rules by which Osaühing Ida Portal, registry code 10970449 (the “Operator”, “we”), protects information when it provides its services under the name Security Test Team.
1.2
The Policy applies to all information that the Operator receives from clients or obtains while it performs a security check or a security assessment, to the website of the Operator and to the systems in which such information is processed.
1.3
The Policy binds the members of the management board, the employees and the contractors of the Operator (the “Personnel”).
2.Principles
2.1
The Operator protects the confidentiality, the integrity and the availability of information.
2.2
The Operator collects and keeps only the information that the task requires, and only for as long as the task requires.
2.3
Access to information is granted to the persons who need it for the task, and to no one else.
2.4
The Operator acts on the systems of a client only with the written authorisation of their owner and within the scope of that authorisation.
3.Responsibility
3.1
The management board of the Operator is responsible for this Policy, for the resources that its implementation requires and for its review.
3.2
Every person of the Personnel undertakes in writing to keep information confidential before obtaining access to the information of a client. The undertaking remains in force after the cooperation with that person has ended.
3.3
The Personnel is bound by the Code of Ethics. A breach of this Policy or of the Code ends the cooperation with the person responsible.
4.Information of clients
4.1
The following is confidential: the fact that a person is a client of the Operator, the content of requests and contracts, the information about the systems of a client, vulnerabilities, evidence, reports and the correspondence with a client.
4.2
Confidential information is disclosed only to the client it concerns and to the persons the client has named in writing. Vulnerabilities, evidence and reports are passed on only to the client or the owner of the system concerned and, with its written consent, to those who remedy the vulnerabilities or coordinate their remedy. Requests and correspondence are also processed by the suppliers of Section 10, to the extent their service requires.
4.3
Information about one client is not used in the work for another client.
4.4
The code, the data and the vulnerabilities of a client are not submitted to public services of artificial intelligence and are not used to train models.
5.Access control
5.1
Every person of the Personnel works under a personal account. Shared accounts are not used.
5.2
Access to the systems in which the information of clients is processed is protected by multi-factor authentication.
5.3
Access to the information of an engagement is granted to the specialists assigned to that engagement and is withdrawn when the engagement is closed or the person leaves it.
5.4
Credentials that a client provides for testing are used only for that testing, are stored encrypted and are destroyed when the engagement is closed. The Operator recommends that the client revoke them after the testing.
6.Encryption and transfer
6.1
The information of clients is stored encrypted, both on the devices of the Personnel and in the systems of the Operator.
6.2
Reports, evidence that allows a vulnerability to be reproduced, and credentials are transferred through a secure channel agreed with the client beforehand. They are not sent by email, through messengers or through the forms of the website.
6.3
The key to an encrypted document is communicated through a channel other than the one through which the document is sent.
7.Data of a check and of an assessment
7.1
The Operator records the minimum that proves a vulnerability. Personal data is not copied and is masked in the evidence wherever the proof remains valid.
7.2
If the specialist obtains access to data that is not needed to prove a vulnerability, the specialist stops, does not keep the data and informs the client.
7.3
The working data of an engagement is destroyed 30 days after the engagement is closed. The report is kept for as long as the contract provides.
7.4
Critical and high findings of a paid engagement are reported to the client within 24 hours of confirmation, without waiting for the report.
8.Devices and infrastructure
8.1
The devices on which the information of clients is processed have encrypted storage, a screen lock and supported, up-to-date software.
8.2
Testing is performed from the network addresses stated in the authorisation, so that the client can tell the actions of the Operator from the actions of third parties.
8.3
The tools used for testing are obtained from their official sources and are kept up to date.
9.Website and requests
9.1
The website securitytest.team is protected by the following measures:
- (a)the website is served over encrypted connections only, and browsers are instructed to use no other connections;
- (b)a content security policy permits only the scripts and the styles of the website itself and of the abuse check of the forms;
- (c)the website sets no cookies and contains no analytics or advertising technologies;
- (d)the forms are protected by an automated abuse check, and what is sent through them is validated both in the browser and on the server.
9.2
Requests are processed as follows:
- (a)the service that stores requests cannot be reached from the internet and accepts data from the website only;
- (b)no more than 5 requests are accepted from one network address within 60 minutes;
- (c)the IP address of a requester is stored as a keyed hash; the address itself is not stored;
- (d)a request is erased automatically 365 days after it was received.
9.3
Vulnerabilities of the website are reported as described in the Vulnerability Disclosure Policy.
10.Suppliers
10.1
The Operator engages a supplier who processes the information of clients only if the supplier ensures a level of protection not lower than this Policy requires.
10.2
The suppliers who process personal data are named in the Privacy Policy.
11.Security incidents
11.1
A person of the Personnel who notices a breach of security or suspects one reports it to the management board without delay.
11.2
The Operator contains the incident, establishes its causes and its consequences, and takes measures that prevent its repetition.
11.3
The Operator informs a client whose information is affected by an incident without undue delay and provides the information the client needs in order to respond.
11.4
Where an incident is a personal data breach, the Operator acts in accordance with Articles 33 and 34 of Regulation (EU) 2016/679.
11.5
A suspected breach of the security of the Operator can be reported to info@securitytest.team.
12.Review of the Policy
12.1
The Operator reviews this Policy at least once a year and after every security incident and every material change in its services or systems.
12.2
The version in force is the one published on this page, with the date from which it applies.