Security principles
- Data access restricted to authorised staff and suppliers.
- Roles and permissions to separate operational responsibilities within the platform.
- Credential protection and recommendations for strong passwords and secure authentication.
- Technical logs and monitoring for security, debugging and abuse prevention.
- Backup and recovery procedures appropriate to the active infrastructure.
- Technical updates and maintenance of software dependencies.
Encryption and transmission
Communications with the website and platform must use encrypted channels when the service is in production. Specific measures may depend on the infrastructure and providers adopted.
Access management
The customer is responsible for managing internal users and permissions, removing access that is no longer required and periodically reviewing permissions.
Incident response
Esdra maintains procedures to assess security events, contain incidents, restore the service and report any personal data breaches within the time frames required by applicable law.








