Version: 1.0 | Classification: Public
The purpose of this Security Policy is to describe the technical and organizational measures implemented by Chronos Web Tech Kft. to protect the confidentiality, integrity, and availability of information processed through the Appointio platform.
Security measures are designed to support Confidentiality, Integrity, Availability, Accountability, and Resilience. The Company aims to protect customer information, prevent unauthorized access, reduce cybersecurity risks, detect security incidents, respond effectively to incidents, maintain service availability, and continuously improve security practices.
Access to systems is granted according to the principle of least privilege. The Company implements strong password requirements, secure password hashing, multi-factor authentication for administrative accounts, session management, and protection against brute-force attacks.
Information is protected using HTTPS / TLS encryption, encrypted backups, encrypted storage where appropriate, and encrypted communication channels. Sensitive credentials are securely managed and are not hardcoded into applications.
Infrastructure security measures include firewall protection, network segmentation, intrusion detection, vulnerability scanning, malware protection, operating system hardening, security updates, and dependency management. Software is developed following secure development practices, including input validation, authentication controls, authorization controls, protection against common web vulnerabilities, dependency monitoring, and secure deployment processes.
The Company maintains logs necessary to detect security events, investigate incidents, monitor system health, and troubleshoot operational issues. Access to logs is restricted. Logs are protected against unauthorized modification where technically feasible.
Regular backups are performed. Recovery procedures are tested where appropriate to minimize data loss and service disruption. Security incidents are handled according to documented internal procedures including identification, containment, investigation, remediation, recovery, and documentation. Where legally required, affected customers and supervisory authorities are notified in accordance with applicable law.
The Company regularly reviews software components and infrastructure for known vulnerabilities. Security patches are applied within reasonable timeframes according to risk. Critical vulnerabilities receive priority. Third-party providers are carefully selected, and appropriate contractual safeguards are implemented where providers process personal data.
Personal data is processed in accordance with GDPR, applicable national legislation, the Company's Privacy Policy, and the Company's Data Processing Agreement.
Security is an ongoing process. The Company periodically reviews risks, threats, technologies, procedures, and legal requirements. Policies may be updated as the organization grows.
Security vulnerabilities may be reported to [email protected]. The Company encourages responsible disclosure and will investigate reported security issues in good faith. Questions regarding this Security Policy may be sent to: Chronos Web Tech Kft.
Email: [email protected]