Version: 1.0 | Effective Date: 01. 07. 2026. | Last Updated: 24. 07. 2026.
The purpose of this Information Security Policy is to describe the principles, technical measures, and organizational safeguards implemented by Chronos Web Tech Kft. to protect confidential information, customer data, and personal data processed through its services.
The Company's security program is based on internationally recognized information security principles, including: Confidentiality, Integrity, Availability, Accountability, Least Privilege, Need-to-Know, Defense in Depth, Secure by Design, Privacy by Design, and Privacy by Default.
Infrastructure providers implement physical security measures including controlled facility access, surveillance systems, visitor controls, environmental monitoring, redundant power systems, and fire protection.
The Company implements technical safeguards including HTTPS/TLS encryption, secure DNS, firewall protection, DDoS mitigation, secure server configuration, automatic security updates, vulnerability management, and network segmentation.
Access controls include unique user accounts, strong password requirements, multi-factor authentication, role-based access control (RBAC), least privilege principle, periodic access reviews, and prompt removal of obsolete accounts. Authentication mechanisms include password hashing, session expiration, secure authentication tokens, login monitoring, brute-force protection, and account lockout mechanisms.
The Company protects data using TLS encryption in transit, encrypted backups, encrypted storage where available, and secure API communication. Sensitive credentials are stored using secure industry-standard methods.
The Company maintains logs necessary to support security monitoring, including authentication events, administrative actions, API requests, application errors, security events, and infrastructure events. Audit logs may record account creation, login history, permission changes, configuration changes, critical administrative actions, and security-related events.
The Company performs automated, encrypted backups, with geographically separated locations where applicable and periodic restoration testing.
Vulnerability management activities may include software updates, dependency management, vulnerability monitoring, security testing, penetration testing where appropriate, and configuration reviews. Critical vulnerabilities are prioritized according to risk.
The Company maintains procedures for responding to security incidents including identification, containment, eradication, recovery, and post-incident review. Where legally required, affected parties and supervisory authorities shall be notified in accordance with applicable law.
Providers are expected to implement appropriate technical and organizational security measures. Personnel are expected to maintain confidentiality, use strong authentication, follow internal security procedures, report suspected security incidents, and complete security awareness training where applicable.
The Company follows secure coding practices, code review, dependency management, version control, testing before deployment, and change management. Where AI-assisted development tools are used, reasonable safeguards are applied to protect confidential information. The Company does not intentionally use customer personal data to train publicly available AI models.
Business continuity measures include backups, redundancy, recovery procedures, monitoring, and documented incident handling. Security controls may be updated in response to technological developments, regulatory changes, identified risks, audit findings, and security incidents.
Questions regarding information security may be directed to: Security Contact
Email: [email protected]