Data Protection and Security Policy
Owner: ELEVIS LTD · Effective 11 August 2026
Report suspected vulnerabilities privately to security@elevis.co.uk. Do not include passwords, health records or exploit another person’s account.
Principles
Elevis uses data minimisation, purpose limitation, least privilege, defence in depth and secure defaults. Web and desktop clients are treated as untrusted; the API enforces authentication, ownership, permissions, validation, rate limits and audit controls.
Protective controls
- Encryption in transit; protected password hashing and token storage; short-lived access with revocable sessions.
- Role-based, deny-by-default administrative access, stronger controls for developer and support functions, and auditable elevation.
- Parameterized database access, schema validation, output encoding, security headers, restricted cross-origin access and upload controls.
- Dependency, secret, static and release checks in CI; signed Windows releases and verified HTTPS update channels.
- Backups, service monitoring, log redaction and documented retention. Secrets and full payment details must never be written to logs.
People and suppliers
Access is limited to trained people with an operational need and reviewed when duties change. Suppliers are assessed for purpose, security, data location and contract terms. Production secrets belong in protected configuration and are rotated through controlled procedures when exposure is suspected.
Incidents
Security events are triaged, contained, investigated and recorded. Elevis assesses impact on confidentiality, integrity, availability and people’s rights. Reportable personal-data breaches are notified to the ICO within the applicable deadline where required, and affected people are informed without undue delay where high risk requires it. Evidence is preserved and corrective actions tracked.
Assurance
Security is reviewed during design, code review, deployment and periodic risk assessment. Automated scans supplement rather than replace manual review. Exceptions require an owner, reason, compensating control and expiry date.
