Ir al contenido

TRUST

Security at Defynia

How we protect our own operation and the information our customers trust us with.

We sell security, so we hold ourselves to the standard we recommend to our customers. This page describes how we protect our own operation and the information our customers trust us with.

How we protect access

  • Multi-factor authentication is required on every administrative account and every system that supports it.
  • Access follows least privilege: engineers receive only the permissions a specific engagement requires, and access is revoked when the engagement ends or the person leaves.
  • Credentials for customer environments are stored in an encrypted vault, never in email, chat or spreadsheets.
  • Administrative sessions to customer environments are logged.

How we protect information

  • All traffic to our website and business systems is encrypted in transit with TLS.
  • Company endpoints run endpoint detection and response, full-disk encryption and enforced patching.
  • Backups of our own business systems are encrypted and tested for restoration.
  • Customer data is segregated by customer and retained only as long as the engagement and the law require.

Our people

Our engineers hold current manufacturer certifications for the platforms we deploy, and their training and authorizations are kept up to date for both our United States and Mexico operations. Personnel with access to customer environments are bound by written confidentiality obligations.

Vendors

We review the security posture of the providers that support our operation before onboarding them, and we contract them under confidentiality and data protection terms. A current list of subprocessors is available to customers on request.

Incident response

We maintain a documented incident response procedure with defined roles, containment steps and communication paths. If an incident affects a customer's data, we notify that customer without undue delay and no later than 72 hours after confirming it, together with what we know and the containment measures already in place.

Reporting a security problem

If you believe you have found a vulnerability in our website or services, see our Responsible Disclosure Policy.

Questions from your security team

We answer security questionnaires and vendor assessments as part of the sales process. Write to info@defynia.us and we will route it to the right engineer.