01Our Commitment to Security
Security and trust are central to how INVORG builds and operates digital solutions. We apply a layered, defence-in-depth approach to protect our systems, our clients' data and the communities we serve. This page summarises our approach; specific controls for a given product or engagement are provided under contract.
02Organisational Measures
- Security roles and responsibilities, with oversight of our security programme;
- Staff security-awareness training and confidentiality obligations;
- Access granted on a least-privilege, need-to-know basis and reviewed regularly;
- Documented policies covering acceptable use, access control and incident response.
03Technical Measures
- Encryption of data in transit (TLS) and, where applicable, at rest;
- Strong authentication, including multi-factor authentication for privileged access;
- Network segmentation, firewalls and monitoring;
- Regular patching and vulnerability management.
04Infrastructure & Hosting
Our solutions are built on trusted, enterprise-grade cloud platforms (including Microsoft and Esri technologies) with robust physical and environmental security maintained by the underlying providers. [List hosting regions / providers as applicable.]
05Application Security
- Secure development practices across the software lifecycle;
- Code review and testing prior to release;
- Periodic vulnerability assessments and, where appropriate, penetration testing.
06Data Protection & Privacy
Our data-handling practices are described in our Privacy Policy. We apply data-protection principles — including minimisation, purpose limitation and access controls — across our operations.
07Monitoring & Incident Response
We monitor systems for suspicious activity and maintain an incident-response plan to detect, investigate and remediate security events promptly. In the event of a data breach affecting personal data, we will notify affected parties and relevant authorities in accordance with applicable law. [Confirm notification timelines with your DPO/counsel.]
08Business Continuity
We maintain business-continuity and disaster-recovery plans to ensure critical services remain available and data can be recovered in the event of disruption.
09Third-Party & Vendor Security
Third-party providers are assessed for security posture before engagement and are subject to contractual obligations regarding data protection and security. [List key vendors / assessment process if desired.]
10Responsible Disclosure
If you believe you have discovered a security vulnerability in our systems, please report it responsibly by emailing security@invorg.com. We will acknowledge receipt and work with you to understand and address the issue. We ask that you do not publicly disclose the issue until we have had a chance to remediate it.
11Compliance
We comply with applicable legal and regulatory requirements, including Sri Lanka's Personal Data Protection Act No. 9 of 2022. Where a given product or engagement requires adherence to specific standards or frameworks, this will be specified in the relevant contract. [List certifications or audit frameworks if applicable.]
12Contact
Security questions? Contact us at security@invorg.com.
