Information Security Policy
Gelt.Pro Information Security Policy (ISP)
This Information Security Policy describes the controls and practices Gelt.Pro uses to protect customer, business, and system information from unauthorized access, disclosure, alteration, and destruction.
Questions about this policy can be sent to support@gelt.pro.
1. Purpose and Scope
The purpose of this ISP is to define baseline security requirements for Gelt.Pro systems, services, personnel, and third parties that handle information on behalf of Gelt.Pro. This policy applies to production and non-production environments, cloud services, endpoints, and business processes that support the platform.
2. Security Governance
Gelt.Pro maintains a governance framework that includes:
- Documented security policies, standards, and procedures reviewed periodically.
- Defined roles and responsibilities for security ownership and accountability.
- Risk-based decision making for security controls and operational priorities.
- Management oversight for security initiatives and remediation activities.
3. Risk Management
Security risks are identified, evaluated, and treated based on likelihood and potential business impact. We periodically assess threats, vulnerabilities, and control effectiveness and prioritize remediation activities according to risk level.
4. Asset Management and Data Classification
Information assets are inventoried and categorized according to sensitivity and business criticality. Data handling requirements are applied based on classification, including controls for storage, transmission, retention, and disposal.
5. Access Control
Access to systems and data is controlled through the following principles:
- Least privilege and need-to-know access assignment.
- Unique user identification and strong authentication controls.
- Role-based provisioning, review, and timely deprovisioning.
- Additional controls for privileged and administrative access.
6. Cryptography and Data Protection
Gelt.Pro uses industry-accepted encryption mechanisms to protect sensitive data in transit and at rest where appropriate. Secrets and credentials are managed through controlled processes to reduce the risk of unauthorized disclosure.
7. Secure Development and Change Management
Security is integrated into the software development lifecycle through code review, dependency oversight, and testing practices. Changes to systems and applications follow controlled release processes designed to reduce operational and security risk.
8. Vulnerability and Patch Management
Gelt.Pro monitors for vulnerabilities and applies remediation actions based on severity, exploitability, and system criticality. Security patches are evaluated and deployed within defined timelines aligned to risk.
9. Logging, Monitoring, and Detection
Security-relevant events are logged and monitored to support threat detection, investigation, and response. Monitoring capabilities are continuously improved to identify suspicious activity and unauthorized access attempts.
10. Incident Response
Gelt.Pro maintains incident response procedures for identification, triage, containment, eradication, recovery, and post-incident review. Security incidents are handled according to defined escalation and communication processes.
11. Business Continuity and Recovery
We maintain continuity and recovery practices intended to support service resilience and restoration after disruptive events. Backup and recovery mechanisms are implemented based on business and technical requirements.
12. Third-Party and Supplier Security
Third-party providers that process or access information on behalf of Gelt.Pro are subject to risk-based due diligence and appropriate contractual security requirements.
13. Security Awareness and Training
Personnel with access to systems or data are expected to complete periodic security awareness activities and follow internal security requirements relevant to their role.
14. Compliance and Policy Exceptions
This policy is informed by recognized security control frameworks and compliance principles, including ISO/IEC 27001, SOC 2, and NIST-aligned practices, as applicable to business needs and legal obligations. Any exceptions to this policy require documented review, risk acceptance, and approval by authorized management.
15. Policy Review and Updates
This ISP is reviewed periodically and updated as needed to reflect changes in technology, legal requirements, business operations, and risk posture.
16. Contact
For security and policy-related inquiries, contact support@gelt.pro.
Back to home