Security Policy
Last Updated: January 9, 2024
This Security Policy describes the measures PixelForgez takes to protect the confidentiality, integrity, and availability of data processed through our platform and services. By using our services, you acknowledge the practices described in this document.
1. Scope
This policy applies to all systems, infrastructure, applications, and data managed by PixelForgez, including our web platform, learning management systems, communication tools, and any associated services provided to learners, instructors, and business clients.
2. Data Protection Principles
We process personal and organizational data in accordance with the following principles:
Confidentiality: Access to data is restricted to authorized personnel who require it to perform their duties. All staff with access to sensitive data are subject to confidentiality obligations.
Integrity: We implement controls to prevent unauthorized modification of data. Data validation and integrity checks are applied at system entry and storage points.
Availability: We maintain redundant systems and backup procedures to ensure service continuity and minimize disruption from technical failures or incidents.
3. Access Control
3.1 User Authentication
All user accounts are protected by password-based authentication. We enforce minimum password complexity requirements and encourage the use of multi-factor authentication where available. Session tokens are generated securely and expire after periods of inactivity.
3.2 Role-Based Access
Access to platform features and data is governed by role-based access control. Users are granted the minimum level of access necessary to perform their intended functions. Administrative access is restricted to designated personnel and reviewed periodically.
3.3 Third-Party Access
Where third-party service providers require access to our systems or data, such access is governed by formal agreements and limited to what is strictly necessary. Third parties are evaluated for their security practices prior to engagement.
4. Data Encryption
Data transmitted between users and our platform is encrypted using industry-standard Transport Layer Security (TLS) protocols. Sensitive data stored within our systems is encrypted at rest using recognized encryption standards. Encryption keys are managed securely and rotated on a defined schedule.
5. Network and Infrastructure Security
5.1 Perimeter Controls
Our infrastructure is protected by firewalls, intrusion detection systems, and network segmentation. Access to internal systems from external networks is restricted and monitored. Only necessary ports and services are exposed.
5.2 Vulnerability Management
We conduct regular vulnerability assessments and apply security patches in a timely manner. Critical patches are prioritized and applied as quickly as practicable following release. Our systems are monitored continuously for known vulnerability signatures.
5.3 Secure Development
Our development processes incorporate security reviews, code analysis, and testing prior to deployment. Changes to production systems follow a controlled release process that includes security validation steps.
6. Monitoring and Logging
System activity, authentication events, and administrative actions are logged and retained for security analysis purposes. Logs are protected against unauthorized modification. We monitor for anomalous behavior and potential security incidents on an ongoing basis. Alerts are reviewed by responsible personnel in a timely manner.
7. Incident Response
7.1 Detection and Containment
We maintain an incident response process to detect, assess, and contain security incidents. Upon identification of a potential incident, affected systems may be isolated to prevent further impact while investigation proceeds.
7.2 Notification
In the event of a confirmed security incident that affects user data, we will notify affected parties in accordance with our obligations and as promptly as circumstances allow. Notifications will include a description of the incident, the data involved, and the steps being taken in response.
7.3 Post-Incident Review
Following resolution of a security incident, we conduct a review to identify root causes and implement corrective measures to reduce the likelihood of recurrence.
8. Physical Security
Our services are hosted in data center facilities that implement physical access controls, environmental protections, and surveillance measures. Physical access to servers and network equipment is restricted to authorized personnel. We select hosting providers that maintain recognized security certifications.
9. Backup and Recovery
Data backups are performed on a regular schedule and stored in geographically separate locations. Backup integrity is tested periodically. Recovery procedures are documented and reviewed to ensure they can be executed effectively in the event of a system failure or data loss incident.
10. Employee Security
All personnel with access to platform systems or user data receive security awareness training upon onboarding and on a recurring basis. Background verification is conducted for roles involving access to sensitive data. Employees are required to adhere to internal security policies and report suspected incidents promptly.
11. Vendor and Supply Chain Security
We assess the security posture of vendors and service providers before integration. Vendor relationships are reviewed periodically, and contracts include security and data protection requirements. We monitor for notifications of security issues affecting third-party components used within our platform.
12. Acceptable Use
Users of our platform are expected to use the service in a manner that does not compromise the security of other users or the platform itself. Prohibited activities include unauthorized access attempts, introduction of malicious code, and any action intended to disrupt service availability. Violations may result in suspension of access and further action.
13. Security Assessments
We conduct periodic internal security reviews and may engage qualified external parties to perform independent assessments, including penetration testing. Findings from these assessments are reviewed and addressed according to their severity and risk level.
14. Responsible Disclosure
If you discover a potential security vulnerability in our platform or services, we encourage you to report it to us promptly. Please contact us at support@pixelforgez.com with a description of the issue. We ask that you refrain from publicly disclosing the vulnerability until we have had a reasonable opportunity to investigate and address it. We will acknowledge receipt of your report and keep you informed of our progress.
15. Policy Review and Updates
This Security Policy is reviewed at least annually and updated as necessary to reflect changes in our practices, technology, or applicable requirements. The date at the top of this document indicates when the policy was last revised. Continued use of our services following an update constitutes acceptance of the revised policy.
16. Contact
For questions or concerns regarding this Security Policy, or to report a security issue, please contact us:
PixelForgez
Koivistontie 6, 90410 Oulu, Finland
Email: support@pixelforgez.com
Phone: +358 14 266 4475
Web: pixelforgez.com
Koivistontie 6, 90410 Oulu, Finland
Email: support@pixelforgez.com
Phone: +358 14 266 4475
Web: pixelforgez.com