Ryniqo OÜ · Legal Pack
Legal · Security

Information Security Policy

This Policy sets out the security controls Ryniqo OÜ operates across the RynIQ™ Platform. It is structured around the control domains of ISO/IEC 27001:2022 Annex A and is written to be referenced by enterprise procurement, information security and audit teams.

Version2.0EffectiveOn publication
SupersedesGoverning lawEstonia · EU
Section 01

Governance

The Founder is the accountable executive for information security. Policies are reviewed at least annually and after any material change to the Platform, the threat landscape, or the regulatory environment.

Section 02

Access control

  • Named accounts for all personnel; no shared credentials.
  • Multi-factor authentication required for administrative access, cloud consoles, source control and identity providers.
  • Role-based access with least-privilege defaults and quarterly review.
  • Provisioning and de-provisioning tied to HR events; access revoked on the working day of departure.
  • Break-glass procedures logged, alerted, and reviewed monthly.
Section 03

Authentication and password policy

  • Minimum 12 characters; NIST SP 800-63B-aligned deny-list of breached and common passwords.
  • No forced periodic rotation without cause; rotation required on suspected compromise.
  • Password manager mandatory for personnel.
  • Session timeouts on administrative interfaces.
Section 04

Encryption

  • TLS 1.2 or higher for all data in transit; HSTS enforced on ryniqo.com.
  • AES-256 for data at rest, with managed keys and automatic rotation.
  • Secrets managed via the platform secret store, never committed to source control.
Section 05

Logging and monitoring

  • Structured audit logs for authentication, authorisation, administrative actions and data access.
  • Minimum 12-month retention, tamper-evident storage.
  • Alerts on privileged actions, anomalous access, and known indicators of compromise.
Section 06

Backups and recovery

  • Automated daily encrypted backups of the primary database with point-in-time recovery.
  • Recovery procedures tested at least annually.
  • RPO 24 hours; RTO 24 hours; both under review as the customer base grows.
Section 07

Incident response

  • Named responder available at security@ryniqo.com.
  • Documented severity levels, escalation paths, and customer notification templates.
  • Post-incident reviews are written for every Sev-2 or higher event and shared with affected customers under NDA.
  • Personal-data breach notification to controllers without undue delay and, where feasible, within 72 hours.
Section 08

Business continuity

A written business-continuity plan covers loss of primary cloud region, loss of key personnel, and loss of critical subprocessor. The plan is tested at least annually.

Section 09

Third-party and subprocessor management

  • Security review before engaging any subprocessor that processes personal data.
  • Written contracts imposing equivalent security obligations.
  • Annual review of subprocessor posture; ad-hoc review on material incident.
Section 10

Secure development

  • Peer code review for every change to production code.
  • Automated dependency vulnerability scanning; critical vulnerabilities remediated within 14 days.
  • Separation of development, staging and production environments.
  • No use of production personal data in development or testing.
  • Threat modelling for material new features.
Section 11

Risk management

A risk register is maintained and reviewed at least quarterly. Risks are classified by likelihood and impact, assigned to a named owner, and tracked through remediation.

Section 12

People

  • Background checks proportionate to role and to local law.
  • Written confidentiality obligations for all personnel.
  • Security awareness training on hire and annually.
  • Clean-desk and clear-screen expectations.
Section 13

Physical security

Production infrastructure runs on hyperscale cloud providers with ISO/IEC 27001-certified data centres. Ryniqo personnel work remotely; company devices are encrypted and centrally managed.

Security Roadmap

Where we are, and what is next

We publish where we are, not where we hope to be. The roadmap below is transparent, not aspirational: items in Current are in force today; items in Planned are scoped but not yet delivered. No dates are promised until an item is complete.

StatusControlNotes
CurrentEncryption in transit (TLS 1.3) and at rest (AES-256)Managed via cloud provider primitives.
CurrentRole-based access control (RBAC)Row-level authorisation at the database.
CurrentAudit loggingAccess, admin, and data change events retained for a defined period.
CurrentLeast-privilege access to productionTime-bound elevation; no shared credentials.
CurrentVendor risk review before onboarding a subprocessorSee Subprocessor List.
PlannedSOC 2 Type IIAuditor selection under way.
PlannedISO/IEC 27001:2022 certificationControls already mapped to Annex A; certification pending.
PlannedIndependent penetration testing (annual)Scope: application, infrastructure, AI attack surface.
PlannedAnnual security review with published summaryExecutive-readable, not marketing copy.