Information Security Policy

Gelt.Pro Information Security Policy (ISP)

Effective date: June 30, 2026

This Information Security Policy describes the controls and practices Gelt.Pro uses to protect customer, business, and system information from unauthorized access, disclosure, alteration, and destruction.

Questions about this policy can be sent to support@gelt.pro.

1. Purpose and Scope

The purpose of this ISP is to define baseline security requirements for Gelt.Pro systems, services, personnel, and third parties that handle information on behalf of Gelt.Pro. This policy applies to production and non-production environments, cloud services, endpoints, and business processes that support the platform.

2. Security Governance

Gelt.Pro maintains a governance framework that includes:

  • Documented security policies, standards, and procedures reviewed periodically.
  • Defined roles and responsibilities for security ownership and accountability.
  • Risk-based decision making for security controls and operational priorities.
  • Management oversight for security initiatives and remediation activities.

3. Risk Management

Security risks are identified, evaluated, and treated based on likelihood and potential business impact. We periodically assess threats, vulnerabilities, and control effectiveness and prioritize remediation activities according to risk level.

4. Asset Management and Data Classification

Information assets are inventoried and categorized according to sensitivity and business criticality. Data handling requirements are applied based on classification, including controls for storage, transmission, retention, and disposal.

5. Access Control

Access to systems and data is controlled through the following principles:

  • Least privilege and need-to-know access assignment.
  • Unique user identification and strong authentication controls.
  • Role-based provisioning, review, and timely deprovisioning.
  • Additional controls for privileged and administrative access.

6. Cryptography and Data Protection

Gelt.Pro uses industry-accepted encryption mechanisms to protect sensitive data in transit and at rest where appropriate. Secrets and credentials are managed through controlled processes to reduce the risk of unauthorized disclosure.

7. Secure Development and Change Management

Security is integrated into the software development lifecycle through code review, dependency oversight, and testing practices. Changes to systems and applications follow controlled release processes designed to reduce operational and security risk.

8. Vulnerability and Patch Management

Gelt.Pro monitors for vulnerabilities and applies remediation actions based on severity, exploitability, and system criticality. Security patches are evaluated and deployed within defined timelines aligned to risk.

9. Logging, Monitoring, and Detection

Security-relevant events are logged and monitored to support threat detection, investigation, and response. Monitoring capabilities are continuously improved to identify suspicious activity and unauthorized access attempts.

10. Incident Response

Gelt.Pro maintains incident response procedures for identification, triage, containment, eradication, recovery, and post-incident review. Security incidents are handled according to defined escalation and communication processes.

11. Business Continuity and Recovery

We maintain continuity and recovery practices intended to support service resilience and restoration after disruptive events. Backup and recovery mechanisms are implemented based on business and technical requirements.

12. Third-Party and Supplier Security

Third-party providers that process or access information on behalf of Gelt.Pro are subject to risk-based due diligence and appropriate contractual security requirements.

13. Security Awareness and Training

Personnel with access to systems or data are expected to complete periodic security awareness activities and follow internal security requirements relevant to their role.

14. Compliance and Policy Exceptions

This policy is informed by recognized security control frameworks and compliance principles, including ISO/IEC 27001, SOC 2, and NIST-aligned practices, as applicable to business needs and legal obligations. Any exceptions to this policy require documented review, risk acceptance, and approval by authorized management.

15. Policy Review and Updates

This ISP is reviewed periodically and updated as needed to reflect changes in technology, legal requirements, business operations, and risk posture.

16. Contact

For security and policy-related inquiries, contact support@gelt.pro.

Back to home