Policy 03

Information Security Policy

Version 1.0 · Effective 1 January 2025 · Aligned to ISO/IEC 27001:2022 (certification audit in final stage).

Purpose & scope

This policy defines how we protect the confidentiality, integrity and availability of information across the WinguSuite services. It reflects an Information Security Management System aligned to ISO/IEC 27001:2022, for which we are at the final stage of the certification audit.

Access control

Access is granted on a least-privilege, need-to-know basis through multi-level user rights. Access to all servers uses Datto and a two-factor authentication (2FA) platform, for employees and third-party support agents alike, and is reviewed periodically.

Physical & environmental security

Hosting is at the Lamda Hellix data centre (ISO 9001, ISO/IEC 27001, SOC), with four-level physical access control (perimeter password, building magnetic card, server-room card, locked racks), camera surveillance, and UPS, redundant generators and environmental sensors.

Network & endpoint security

The network is segmented into physical and virtual (VLAN) networks with access-list control. Firewalls, DDoS protection, anti-virus and anti-malware protect the infrastructure. Endpoint detection and response is provided by Acronis EDR with managed detection and response (MDR).

Encryption & backup

Data is encrypted in transit; backups are encrypted with AES-256. Daily backups and replication run through Acronis Cyber Protect Cloud and Veeam, and recovery is tested.

Logging & incident management

Security events are logged and monitored. Incidents are investigated, contained and remediated, and personal-data breaches are handled in line with our GDPR obligations. Report events to [email protected].

← Back to Compliance & Policies