Information Security Policy
This policy is subject to annual audit under ISO/IEC 27001. Certifications page
Eclit undertakes to protect its customers' information assets as it protects its own. Information security is not a compliance obligation for us but a direct part of the service: when a customer hands over their infrastructure, its confidentiality, integrity and availability become our responsibility.
Our information security management system is established and operated in line with ISO/IEC 27001. Risk assessment is repeated at regular intervals and on every significant change, and the controls we select are recorded together with the reasoning behind them.
Access rights are granted on the principle of segregation of duties. No individual holds the authority to erase a system's audit trail alone. Rights are bound to a role, reviewed regularly, and updated immediately when a role changes.
Security incidents are handled through a defined process: detection, containment, remediation and post-incident review. For any incident affecting a customer, notification is made within the period set out in the contract.
All employees receive information security training on joining and at regular intervals thereafter. Compliance with this policy forms part of the employment contract.