Security at 360Synk
We take the security of your data seriously. This statement outlines our security practices.
TODO: Replace this placeholder with final legal text before public launch.
Infrastructure Security
Cloud Hosting
- Hosted on Microsoft Azure UK regions
- ISO 27001 certified data centres
- Redundant systems with automatic failover
Network Security
- Web Application Firewall (WAF)
- DDoS protection
- Network segmentation
- Regular penetration testing
Data Security
Encryption
- TLS 1.3 for data in transit
- AES-256 for data at rest
- Secure key management via Azure Key Vault
Access Control
- Role-based access control (RBAC)
- Multi-factor authentication available
- Single sign-on (SSO) support
- Session management and timeouts
Application Security
Development Practices
- Secure development lifecycle
- Code reviews
- Automated security testing
- Dependency vulnerability scanning
Monitoring
- 24/7 system monitoring
- Anomaly detection
- Security event logging
- Incident response procedures
Compliance
- GDPR compliant
- UK Data Protection Act 2018
- Regular third-party audits
- Annual penetration testing
Incident Response
We maintain documented incident response procedures:
1. Detection and analysis
2. Containment
3. Eradication
4. Recovery
5. Post-incident review
Reporting Security Issues
If you discover a security vulnerability, please report it to security@360synk.co.uk
We operate a responsible disclosure programme and will acknowledge reports within 24 hours.
Updates
This statement is reviewed and updated regularly.
Last updated: January 2025