Legal
Security Policy
Public overview of Farqad Cloud information security practices.
Purpose
This public Security Policy summarizes how Farqad Cloud approaches information security for systems we build and operate. It is intentionally non-exhaustive and avoids details that would assist attackers. Additional evidence is available to authorized parties via the Trust Center.
Program overview
We build and operate with documented practices informed by recognized information-security and secure-software-delivery guidance. We do not present certification badges or independent attestations on this site unless current written evidence exists.
Governance
- Assigned security ownership and management review
- Risk assessment for material systems
- Vendor/subprocessor review before onboarding
- Policy review at least annually
Access control
- Least privilege and role-based access
- Multifactor authentication for privileged access
- Joiner/mover/leaver reviews for staff and contractors
Secure development
- Peer review and protected branches for material codebases
- Dependency and secret scanning in CI where systems are in scope
- Environment separation and no production secrets in source control
- Vulnerability remediation tracked by severity
Cloud and data protection
- Encryption in transit (TLS) for the public website and client connections we control
- Encryption at rest for systems where we manage storage configuration
- Backups and restoration testing on a defined schedule for in-scope systems
- Logging and monitoring for security-relevant events
Vulnerability management
We monitor dependencies, patch on a risk basis, and welcome reports under the Responsible Disclosure Policy.
Incident response
We maintain an incident process covering detection, containment, eradication, recovery, and stakeholder communication. Customer-impacting personal-data incidents are handled under the DPA and applicable law.
What we do not claim
We do not claim to be unhackable, or certified under any framework, or an official partner of cloud or payment vendors, unless current written evidence is published with our approval.
Change notification
We may update this policy to reflect legal, operational, or service changes. Material changes will be communicated on this page or through another appropriate notice. Where required by law or contract, we will provide additional notice. Where affirmative consent or a contractual amendment is required, continued use alone will not replace that process.