LEGAL
Information security policy
The controls we apply to client data and delivered platforms, how we respond to incidents, and how to report a vulnerability responsibly.
Effective 16 August 2026
Our approach
Lunava Digital Solutions FZCO works with public institutions, enterprises and development organisations, so security is treated as a delivery requirement rather than a later hardening step. This policy sets out the measures we apply as standard. Engagement-specific requirements are agreed in the services contract and can be extended where a client's own framework demands it.
Organisational measures
We maintain the following practices across the business:
- Confidentiality obligations for all personnel and contractors
- Access to client data on a least-privilege, need-to-know basis, reviewed when roles change
- Multi-factor authentication on business accounts and administrative tooling
- Security awareness expectations covering phishing, credential handling and device hygiene
- Documented onboarding and offboarding, including prompt revocation of access
- Due diligence and written terms before a service provider handles client or personal data
Technical measures
For the systems we build and operate:
- Encryption in transit using current TLS, and encryption at rest through the underlying platform
- Role-based access control, audit trails and activity logging in delivered portals
- Secrets held in managed secret stores, never in source code or documents
- Input validation, output encoding and protection against common web vulnerabilities
- Dependency and vulnerability monitoring, with patching prioritised by severity
- Environment separation between development, staging and production
- Backup and restore procedures appropriate to the platform's availability requirements
- Change control with peer review before production releases
Data handling
We collect and retain only what a purpose requires, use production data in non-production environments only when a client authorises it and it is masked or minimised, and delete or return client data at the end of an engagement in line with the agreed retention schedule.
Incident response
We operate a documented incident process covering detection, triage, containment, eradication, recovery and post-incident review. Where an incident affects a client's data we notify the client without undue delay with the facts known at the time, and support any regulatory or individual notification the client must make.
Where we are the controller and a personal data breach is likely to result in risk to individuals, we notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals where the risk is high.
Business continuity
Delivery depends on managed cloud infrastructure with provider-level resilience. Continuity and recovery objectives for a specific platform are agreed with the client and tested at a frequency proportionate to the platform's criticality.
Reporting a vulnerability
Send security reports to support@lunavadigital.com with the subject line "Security". Include enough detail to reproduce the issue and avoid accessing, modifying or exfiltrating data beyond what is needed to demonstrate it. We acknowledge within five working days, keep you updated on remediation, and will credit reporters who ask for it.
Assurance
We are happy to complete client security questionnaires, take part in due diligence reviews, and agree contractual security schedules, audit rights and penetration testing arrangements as part of contracting.
All Lunava policies are listed in our legal centre.