Policy 03
Information Security Policy
Purpose & scope
This policy defines how we protect the confidentiality, integrity and availability of information across the WinguSuite services. It reflects an Information Security Management System aligned to ISO/IEC 27001:2022, for which we are at the final stage of the certification audit.
Access control
Access is granted on a least-privilege, need-to-know basis through multi-level user rights. Access to all servers uses Datto and a two-factor authentication (2FA) platform, for employees and third-party support agents alike, and is reviewed periodically.
Physical & environmental security
Hosting is at the Lamda Hellix data centre (ISO 9001, ISO/IEC 27001, SOC), with four-level physical access control (perimeter password, building magnetic card, server-room card, locked racks), camera surveillance, and UPS, redundant generators and environmental sensors.
Network & endpoint security
The network is segmented into physical and virtual (VLAN) networks with access-list control. Firewalls, DDoS protection, anti-virus and anti-malware protect the infrastructure. Endpoint detection and response is provided by Acronis EDR with managed detection and response (MDR).
Encryption & backup
Data is encrypted in transit; backups are encrypted with AES-256. Daily backups and replication run through Acronis Cyber Protect Cloud and Veeam, and recovery is tested.
Logging & incident management
Security events are logged and monitored. Incidents are investigated, contained and remediated, and personal-data breaches are handled in line with our GDPR obligations. Report events to [email protected].