Information Security Policy
How we protect your data and ensure the security of our platform.
Last updated: February 2026
1. Introduction
WetrackWise is committed to protecting client data and maintaining the highest standards of information security. This policy outlines our comprehensive information security programme, covering all systems, data, and personnel involved in delivering our services.
This policy applies to all systems that process, store, or transmit client data, as well as all personnel who have access to such systems.
2. Data Protection
- All data encrypted at rest using industry-standard AES-256 encryption
- All data encrypted in transit using TLS 1.2+
- Sensitive credentials (API keys, tokens) stored in dedicated encrypted secret management systems
- Database backups encrypted and stored in geographically redundant locations
- Regular integrity checks on stored data
3. Access Control
- Multi-factor authentication enforced for all user accounts
- Role-based access control (RBAC) with principle of least privilege
- Session management with automatic expiration and secure token handling
- Unique credentials per user — no shared accounts
- Regular access reviews and deprovisioning for offboarded personnel
4. Infrastructure Security
- Hosted on enterprise-grade cloud infrastructure with SOC 2, ISO 27001, and GDPR compliance certifications
- Network segmentation and isolation between environments (production, staging)
- Web Application Firewall (WAF) protecting all public endpoints
- DDoS mitigation at the network and application layers
- Automated security patching and vulnerability scanning
- Immutable infrastructure — servers are replaced, not modified
5. Third-Party Integration Security
- All marketplace integrations use OAuth 2.0 with short-lived access tokens
- Refresh tokens stored encrypted and rotated automatically
- Webhook payloads verified using HMAC signature validation
- Third-party API credentials never logged or exposed in error messages
- Minimum required scopes requested for each integration
- Regular review of third-party access and permissions
6. Application Security
- Secure development lifecycle (SDLC) with code review for all changes
- Input validation and output encoding to prevent injection attacks
- Protection against OWASP Top 10 vulnerabilities
- Content Security Policy (CSP) and security headers on all responses
- Dependency scanning for known vulnerabilities
- Automated security testing in CI/CD pipeline
7. Incident Response
- Documented incident response plan with defined roles and escalation procedures
- 24-hour initial response commitment for critical security incidents
- Affected users notified within 72 hours of confirmed data breach (per LGPD/GDPR)
- Post-incident review and remediation for every security event
- Regular incident response drills and plan updates
8. Monitoring & Logging
- Continuous monitoring of all systems and endpoints
- Centralized log management with tamper-evident audit trails
- Real-time alerting on suspicious activity and anomalies
- Log retention aligned with regulatory requirements
- Regular review of monitoring coverage and alert thresholds
9. Personnel Security
- Security awareness training for all team members
- Background verification for personnel with access to sensitive systems
- Principle of least privilege applied to all internal access
- Immediate access revocation upon role change or departure
- Confidentiality agreements for all personnel and contractors
10. Data Retention & Disposal
- Data retained only as long as necessary for service delivery and legal obligations
- Marketplace data retained per connection lifecycle — deleted upon disconnection at user request
- Secure deletion procedures ensuring data is irrecoverable
- Regular audits of retained data against retention policy
11. Compliance
LGPD (Brazil)
Compliant with LGPD (Brazil's General Data Protection Law), ensuring transparent data processing with documented legal bases for all personal data handling.
GDPR (European Union)
GDPR-aligned practices for European users, including data minimisation, purpose limitation, and support for data subject rights.
- Regular internal security assessments and policy reviews
- Data Processing Agreements (DPA) available for enterprise clients
12. Contact
For security concerns or to report vulnerabilities: security@wetrackwise.com
For privacy-related requests: support@wetrackwise.com