Information Security Policy
This Policy sets out the security controls Ryniqo OÜ operates across the RynIQ™ Platform. It is structured around the control domains of ISO/IEC 27001:2022 Annex A and is written to be referenced by enterprise procurement, information security and audit teams.
| Version | 2.0 | Effective | On publication |
|---|---|---|---|
| Supersedes | — | Governing law | Estonia · EU |
Governance
The Founder is the accountable executive for information security. Policies are reviewed at least annually and after any material change to the Platform, the threat landscape, or the regulatory environment.
Access control
- Named accounts for all personnel; no shared credentials.
- Multi-factor authentication required for administrative access, cloud consoles, source control and identity providers.
- Role-based access with least-privilege defaults and quarterly review.
- Provisioning and de-provisioning tied to HR events; access revoked on the working day of departure.
- Break-glass procedures logged, alerted, and reviewed monthly.
Authentication and password policy
- Minimum 12 characters; NIST SP 800-63B-aligned deny-list of breached and common passwords.
- No forced periodic rotation without cause; rotation required on suspected compromise.
- Password manager mandatory for personnel.
- Session timeouts on administrative interfaces.
Encryption
- TLS 1.2 or higher for all data in transit; HSTS enforced on ryniqo.com.
- AES-256 for data at rest, with managed keys and automatic rotation.
- Secrets managed via the platform secret store, never committed to source control.
Logging and monitoring
- Structured audit logs for authentication, authorisation, administrative actions and data access.
- Minimum 12-month retention, tamper-evident storage.
- Alerts on privileged actions, anomalous access, and known indicators of compromise.
Backups and recovery
- Automated daily encrypted backups of the primary database with point-in-time recovery.
- Recovery procedures tested at least annually.
- RPO 24 hours; RTO 24 hours; both under review as the customer base grows.
Incident response
- Named responder available at security@ryniqo.com.
- Documented severity levels, escalation paths, and customer notification templates.
- Post-incident reviews are written for every Sev-2 or higher event and shared with affected customers under NDA.
- Personal-data breach notification to controllers without undue delay and, where feasible, within 72 hours.
Business continuity
A written business-continuity plan covers loss of primary cloud region, loss of key personnel, and loss of critical subprocessor. The plan is tested at least annually.
Third-party and subprocessor management
- Security review before engaging any subprocessor that processes personal data.
- Written contracts imposing equivalent security obligations.
- Annual review of subprocessor posture; ad-hoc review on material incident.
Secure development
- Peer code review for every change to production code.
- Automated dependency vulnerability scanning; critical vulnerabilities remediated within 14 days.
- Separation of development, staging and production environments.
- No use of production personal data in development or testing.
- Threat modelling for material new features.
Risk management
A risk register is maintained and reviewed at least quarterly. Risks are classified by likelihood and impact, assigned to a named owner, and tracked through remediation.
People
- Background checks proportionate to role and to local law.
- Written confidentiality obligations for all personnel.
- Security awareness training on hire and annually.
- Clean-desk and clear-screen expectations.
Physical security
Production infrastructure runs on hyperscale cloud providers with ISO/IEC 27001-certified data centres. Ryniqo personnel work remotely; company devices are encrypted and centrally managed.