Security Policy

Last updated: November 7, 2024

Ravixo Cunel is committed to protecting the security and integrity of all data processed through the ravixocunel.com platform. This Security Policy describes the technical and organizational measures we maintain to safeguard our systems, your account, and the information you entrust to us.


1. Scope

This policy applies to all systems, infrastructure, services, and personnel involved in the operation of ravixocunel.com. It covers data in transit, data at rest, access controls, incident management, and third-party relationships relevant to platform security.


2. Infrastructure Security

2.1 Hosting and Network

Our platform is hosted on infrastructure that maintains industry-standard physical and environmental controls. Data centers used by our hosting providers implement access restrictions, surveillance, and redundancy measures. Network traffic is monitored and filtered to detect and prevent unauthorized access attempts.

2.2 Encryption in Transit

All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS). We enforce a minimum of TLS 1.2 and prefer TLS 1.3 where supported. Unencrypted HTTP connections are automatically redirected to HTTPS.

2.3 Encryption at Rest

Sensitive data stored in our databases and file systems is encrypted at rest using strong encryption algorithms. Encryption keys are managed through dedicated key management practices and are rotated on a scheduled basis.

2.4 System Hardening

Servers and services are configured according to hardening guidelines. Unnecessary services, ports, and protocols are disabled. Operating systems and software dependencies are kept up to date with security patches applied promptly following disclosure.


3. Access Control

3.1 Principle of Least Privilege

Access to systems, databases, and user data is granted only to personnel who require it to perform their job responsibilities. Permissions are reviewed regularly and revoked promptly when no longer needed.

3.2 Authentication

Administrative access to production systems requires strong authentication mechanisms. Multi-factor authentication is enforced for all personnel with privileged access. Shared credentials are not permitted.

3.3 User Account Security

User passwords are stored using adaptive one-way hashing functions. We do not store passwords in plaintext or in reversibly encrypted form. Users are encouraged to choose strong, unique passwords and to enable any available account security features.

3.4 Session Management

User sessions are protected against common attacks including session fixation and cross-site request forgery. Sessions expire after periods of inactivity and upon explicit logout. Session tokens are transmitted only over encrypted connections.


4. Application Security

4.1 Secure Development Practices

Security considerations are integrated throughout our software development lifecycle. Code changes undergo review processes before deployment. We follow established guidelines for preventing common vulnerabilities including those described in industry-recognized security frameworks.

4.2 Vulnerability Management

We conduct periodic security assessments of our platform and infrastructure. Identified vulnerabilities are prioritized and remediated based on their severity and potential impact. Critical vulnerabilities are addressed on an expedited basis.

4.3 Dependency Management

Third-party libraries and software components used in our platform are monitored for known security vulnerabilities. Updates and patches are applied in a timely manner. Dependencies are sourced from reputable repositories and verified for integrity where possible.

4.4 Input Validation and Output Encoding

User-supplied input is validated and sanitized before processing. Output is encoded appropriately to prevent injection attacks. Parameterized queries are used for all database interactions to prevent SQL injection.


5. Data Protection

5.1 Data Minimization

We collect and retain only the data necessary to provide our services. Data that is no longer required for its original purpose is securely deleted or anonymized in accordance with our data retention practices.

5.2 Backups

Regular backups of platform data are performed and stored securely. Backup integrity is verified periodically. Backups are encrypted and access to backup storage is restricted to authorized personnel.

5.3 Data Isolation

User data is logically isolated to prevent unauthorized cross-account access. Database queries and application logic are designed to enforce strict data separation between accounts.


6. Monitoring and Logging

Our systems generate logs of security-relevant events including authentication attempts, access to sensitive resources, and configuration changes. Logs are stored securely, protected against tampering, and retained for a defined period to support incident investigation. Automated monitoring systems alert our team to anomalous activity.


7. Incident Response

7.1 Detection and Response

We maintain an incident response process for identifying, containing, and remediating security incidents. Our team is trained to respond to security events in a timely and structured manner.

7.2 Notification

In the event of a security incident that affects user data, we will notify affected users and relevant parties in accordance with applicable legal obligations. Notifications will be provided through appropriate channels without undue delay following our assessment of the incident.

7.3 Post-Incident Review

Following any significant security incident, we conduct a review to identify root causes and implement measures to prevent recurrence. Lessons learned are incorporated into our security practices.


8. Third-Party Security

We work with third-party service providers who may process or store data on our behalf. We evaluate the security practices of such providers before engagement and require them to maintain appropriate security standards. Data processing agreements are established with providers who handle personal data. A list of key sub-processors is available upon request at info@ravixocunel.com.


9. Physical Security

Our team members who access production systems do so through secured, access-controlled environments. Devices used to access production infrastructure are managed according to endpoint security standards including encryption, screen lock policies, and remote wipe capability.


10. Employee Security Practices

Personnel with access to systems or user data receive security awareness training. Background considerations are part of our hiring process for roles with privileged access. Employees are bound by confidentiality obligations and acceptable use policies. Access is revoked promptly upon termination of employment or engagement.


11. Responsible Disclosure

We welcome reports from security researchers and users who identify potential vulnerabilities in our platform. If you believe you have discovered a security issue, please report it to us at info@ravixocunel.com. We request that you:

Expectation Detail
Responsible handling Do not access, modify, or delete data beyond what is necessary to demonstrate the vulnerability
Private disclosure Report the issue to us before any public disclosure to allow time for investigation and remediation
No disruption Do not perform actions that degrade the availability or performance of our services
Good faith Act in good faith with the intent of improving security rather than causing harm

We will acknowledge receipt of your report and keep you informed of our progress. We will not pursue legal action against researchers who act in good faith in accordance with this disclosure guidance.


12. Compliance and Certifications

We align our security practices with recognized industry standards and frameworks. Our security posture is reviewed periodically against current best practices. We cooperate with lawful requests from competent authorities in accordance with applicable law and our legal obligations.


13. Changes to This Policy

We may update this Security Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the date at the top of this document and notify users through appropriate channels. We encourage you to review this policy periodically.


14. Contact

If you have questions about this Security Policy or our security practices, please contact us:

Channel Details
Email info@ravixocunel.com
Phone +380414418625
Address Oleksandra Myshuhy St, 8, Kyiv, Ukraine, 02000
Website ravixocunel.com