Security Policy

Last Updated: December 8, 2024


Offerzuno ("we", "us", or "our") is committed to protecting the security of information processed through our platform and services available at offerzuno.life. This Security Policy describes the technical and organisational measures we implement to safeguard data, maintain service integrity, and respond to security incidents.


1. Scope

This policy applies to all systems, infrastructure, applications, and services operated by Offerzuno, including web-based interfaces, backend services, data storage systems, and third-party integrations used in the delivery of our office yoga class organisation services.

2. Information Security Principles

Our security programme is built on the following core principles:

Confidentiality: Access to data is restricted to authorised personnel and systems only. We apply least-privilege access controls across all environments.

Integrity: We implement controls to prevent unauthorised modification of data, both in transit and at rest.

Availability: We maintain infrastructure redundancy and monitoring to ensure our services remain accessible and resilient against disruption.

3. Data Encryption

3.1 Data in Transit

All data transmitted between users and our services is encrypted using industry-standard Transport Layer Security (TLS 1.2 or higher). Unencrypted connections are not accepted on any public-facing endpoint.

3.2 Data at Rest

Sensitive data stored within our systems is encrypted using strong encryption algorithms. Encryption keys are managed through dedicated key management practices with restricted access and regular rotation schedules.

4. Access Control

We enforce strict access control measures across all internal systems:

Authentication: All internal systems require authenticated access. Multi-factor authentication (MFA) is enforced for privileged accounts and administrative interfaces.

Authorisation: Access rights are granted based on role and operational necessity. Permissions are reviewed periodically and revoked upon role change or termination.

Session Management: User sessions are managed with appropriate timeout controls and secure session token handling.

5. Infrastructure Security

5.1 Network Security

Our infrastructure is protected by network segmentation, firewalls, and intrusion detection systems. Traffic between system components is restricted to defined and necessary communication paths only.

5.2 Vulnerability Management

We conduct regular vulnerability assessments and apply security patches in a timely manner. Critical vulnerabilities are addressed on an expedited basis following discovery or disclosure.

5.3 Monitoring and Logging

System activity, access events, and security-relevant actions are logged and monitored continuously. Logs are retained for a defined period and reviewed for anomalous behaviour.

6. Application Security

Security is integrated throughout our software development lifecycle. Our practices include:

Secure Coding: Development teams follow secure coding guidelines to prevent common vulnerabilities including injection attacks, cross-site scripting, and insecure data handling.

Code Review: Changes to application code undergo review processes that include security considerations prior to deployment.

Dependency Management: Third-party libraries and dependencies are tracked and updated to address known security issues.

Testing: Security testing is performed as part of the release process, including functional and boundary testing relevant to security controls.

7. Third-Party and Vendor Security

We evaluate third-party service providers and vendors for their security posture before engagement. Contracts with third parties that process or access data on our behalf include appropriate security obligations. We review significant third-party relationships periodically to ensure continued compliance with our security expectations.

8. Physical Security

Our services are hosted in data centre facilities that maintain physical security controls including restricted access, surveillance, environmental monitoring, and redundant power and cooling systems. Physical access to production infrastructure is limited to authorised personnel only.

9. Incident Response

9.1 Detection and Containment

We maintain an incident response process to detect, assess, and contain security events in a timely manner. Our monitoring systems are configured to generate alerts for events that may indicate a security incident.

9.2 Notification

In the event of a confirmed security incident that affects user data or service availability, we will notify affected parties in accordance with our legal obligations and within reasonable timeframes given the nature of the incident.

9.3 Post-Incident Review

Following resolution of a security incident, we conduct a review to identify root causes, assess the effectiveness of our response, and implement improvements to prevent recurrence.

10. Business Continuity and Disaster Recovery

We maintain business continuity and disaster recovery plans to ensure that critical services can be restored following a significant disruption. These plans are reviewed and tested periodically. Data backups are performed on a regular schedule, encrypted, and stored in geographically separate locations where applicable.

11. Employee Security

All personnel with access to systems or data are subject to security awareness training. Access is provisioned based on job function and reviewed regularly. Personnel are required to adhere to internal security policies and acceptable use standards. Access is revoked promptly upon departure or role change.

12. Security Updates and Patch Management

We maintain a patch management process to ensure that operating systems, application software, and infrastructure components are updated in a timely manner. The severity and exploitability of vulnerabilities are considered when prioritising patch deployment timelines.

13. Responsible Disclosure

If you believe you have identified a security vulnerability in our systems or services, we encourage responsible disclosure. Please contact us at info@offerzuno.life with a description of the issue. We commit to acknowledging reports promptly and working to address confirmed vulnerabilities in a reasonable timeframe. We ask that you do not publicly disclose potential vulnerabilities until we have had the opportunity to investigate and remediate.

14. Changes to This Policy

We may update this Security Policy from time to time to reflect changes in our practices, technology, or legal obligations. When we make material changes, we will update the "Last Updated" date at the top of this document. We encourage you to review this policy periodically.

15. Contact

If you have questions about this Security Policy or our security practices, you may contact us through the following:

Offerzuno
18 Hodgkinson St, Griffith ACT 2603, Australia
Email: info@offerzuno.life
Phone: +61 448 831 922