Published security program

Information Security Policy

Eunoiana Digital Solutions maintains an information security program designed to protect client data, project assets, credentials and production systems throughout design, development, deployment and support.

Owner: Eunoiana Digital Solutions Effective date: 18 April 2026 Review cycle: At least annually

Policy Statement

Eunoiana Digital Solutions is committed to handling information responsibly and applying practical safeguards that are appropriate for the size, scope and risk profile of each project. Security is considered during discovery, design, development, testing, launch and ongoing maintenance.

This policy applies to Eunoiana Digital Solutions systems, development environments, client project assets, source code, credentials, documentation and third-party services used to deliver work for clients.

Governance and Responsibility

Responsibility for information security sits with Eunoiana Digital Solutions leadership. Security requirements are reviewed during project planning, and project-specific risks are considered before sensitive data, integrations or production access are handled.

Access Control

Access to client systems, repositories, hosting accounts and third-party tools is granted only where needed to deliver agreed work. Strong passwords and multi-factor authentication are used wherever supported. Access is removed when it is no longer required.

Secure Development

Eunoiana Digital Solutions follows secure development practices including code review where appropriate, dependency awareness, environment separation, least-privilege configuration, input validation and careful handling of authentication, permissions and secrets.

Data Handling

Client data is used only for agreed business purposes. Sensitive data is limited to what is necessary, stored in approved systems, and not shared with third parties except where required for delivery, support or legal compliance.

Credentials and Secrets

API keys, passwords, tokens and production secrets are not intentionally committed to public code repositories. Where credentials are needed, they are stored using suitable password managers, hosting environment variables or platform secret management.

Third-Party Services

Eunoiana Digital Solutions uses reputable third-party platforms for hosting, development, communication, analytics, payments, email, automation and project delivery. Service choices are reviewed for suitability, reliability and reasonable security controls.

Backups and Continuity

Project source code and key project assets are maintained in controlled repositories or approved storage locations. Where Eunoiana Digital Solutions manages live systems, backup and recovery expectations are agreed with the client based on business need.

Incident Response

Suspected security incidents are investigated promptly. Where an incident may affect a client, Eunoiana Digital Solutions will notify the client, support containment and remediation, and document follow-up actions to reduce the likelihood of recurrence.

Review and Improvement

This policy is reviewed at least annually and may be updated sooner when Eunoiana Digital Solutions introduces new services, tools, hosting arrangements, regulatory requirements or operational processes.

Questions about this policy can be sent through the contact form.

Related Security Controls

Eunoiana Digital Solutions also publishes summaries of its network segregation, hosting, network threat protection, endpoint security, daily operational security, access control, data classification, incident response, vulnerability management, personal data protection and privacy practices.

View network security controls

View endpoint security controls

View operational security baseline

View access control policy

View data classification and encryption policy

View incident response policy

View vulnerability and threat management procedure

View personal data protection policy

View privacy policy