{% extends "base.html" %} {% block title %}Security Policy - MyWebdav{% endblock %} {% block description %}Security Policy for MyWebdav cloud storage service.{% endblock %} {% block extra_css %} {% endblock %} {% block content %}
Last Updated: November 16, 2025
This policy establishes the framework for securing our cloud storage platform and ensures all personnel understand their security responsibilities.
Applies to all employees, contractors, systems, and data managed by MyWebdav Technologies.
We maintain an ISO/IEC 27001-certified ISMS with regular risk assessments, audits, and continuous improvement.
Access follows the principle of least privilege with multi-factor authentication required for administrative access.
Strong passwords, regular rotation, and account lockout policies are enforced.
Secured via VPN with full logging and monitoring.
Data classified as Public, Internal, Confidential, or Highly Sensitive with appropriate controls.
Data retained only as necessary with secure deletion methods.
Isolated networks with firewalls, IDS, and regular monitoring.
Hardened systems following CIS Benchmarks.
Controlled access to data centers with biometric authentication.
Secure storage in climate-controlled environments.
Comprehensive plan for identification, containment, eradication, recovery, and notification.
Incidents reported within 72 hours (GDPR) or 24 hours (NIS2) as applicable.
Code reviews, static/dynamic analysis, and vulnerability management.
Formal approval processes for production changes.
Security assessments and contractual requirements for all vendors.
Compliance with GDPR, NIS2, and ISO/IEC 27001.
Annual audits, quarterly penetration testing, and continuous monitoring.
Mandatory annual security training for all personnel.
Compliance is mandatory. Violations may result in disciplinary action up to termination.
If you have any questions about this security policy, please contact us: