Security Policy
Last updated: October 12, 2024
Dantrok is committed to protecting the security of its platform, services, and the data entrusted to us by our users. This Security Policy describes the measures we take to safeguard information, maintain system integrity, and respond to security incidents.
1. Scope
This policy applies to all systems, infrastructure, applications, and processes operated by Dantrok under the domain dantrok.com. It covers all data processed through our platform, including user accounts, session data, payment information, and learning records.
2. Data Protection Principles
We apply the following core principles to all data security practices:
Confidentiality: Access to data is restricted to authorised personnel and systems only.
Integrity: Data is protected from unauthorised modification or corruption through technical and procedural controls.
Availability: Systems are maintained to ensure reliable access for legitimate users, with measures in place to prevent and recover from disruptions.
3. Access Control
3.1 User Authentication
All user accounts are protected by password-based authentication. We strongly encourage users to enable multi-factor authentication where available. Passwords are stored using industry-standard one-way hashing algorithms and are never stored in plaintext.
3.2 Internal Access
Access to production systems and sensitive data by Dantrok staff is governed by the principle of least privilege. Access rights are reviewed periodically and revoked promptly upon role change or departure. All internal access to sensitive systems is logged and monitored.
3.3 Session Management
User sessions are managed using secure, time-limited tokens. Sessions are invalidated upon logout and after a defined period of inactivity. Session identifiers are transmitted exclusively over encrypted connections.
4. Data Transmission Security
All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS). We enforce HTTPS across all endpoints and do not permit unencrypted connections. Our TLS configurations are reviewed and updated regularly to reflect current best practices.
5. Data Storage Security
Data at rest is stored using encrypted storage systems. Sensitive fields, including payment credentials and authentication tokens, receive additional layers of encryption. Backups are encrypted and stored in geographically separate locations to support recovery in the event of a system failure.
6. Infrastructure Security
6.1 Network Security
Our infrastructure is protected by firewalls, network segmentation, and intrusion detection systems. Traffic is monitored continuously for anomalous patterns. Administrative interfaces are not exposed to the public internet and are accessible only through secured channels.
6.2 Vulnerability Management
We conduct regular vulnerability assessments and apply security patches to operating systems, dependencies, and third-party components in a timely manner. Critical vulnerabilities are prioritised for immediate remediation.
6.3 Third-Party Services
We evaluate the security posture of third-party service providers before integration. Vendors who handle user data are required to maintain security standards consistent with this policy. Data sharing with third parties is limited to what is necessary for service delivery.
7. Application Security
Our development practices incorporate security at every stage of the software lifecycle. Code undergoes review processes that include security considerations. We apply protections against common vulnerabilities including but not limited to injection attacks, cross-site scripting, cross-site request forgery, and broken authentication. Dependency libraries are monitored for known vulnerabilities.
8. Monitoring and Logging
System activity, access events, and error conditions are logged to support security monitoring and incident investigation. Logs are retained for a defined period and protected from unauthorised access or modification. Automated alerting is in place to notify our security team of suspicious activity.
9. Incident Response
9.1 Detection and Containment
Upon detection of a potential security incident, our team initiates a structured response process. The immediate priority is to contain the incident and prevent further impact to systems or data.
9.2 Investigation
We investigate the cause, scope, and impact of the incident using available logs and system telemetry. Affected systems are preserved for forensic review where appropriate.
9.3 Notification
Where a security incident results in unauthorised access to or disclosure of user data, we will notify affected users in a timely manner. Notification will include a description of the incident, the categories of data involved, and the steps we have taken or recommend users take in response.
9.4 Post-Incident Review
Following resolution of an incident, we conduct a review to identify contributing factors and implement measures to prevent recurrence.
10. Physical Security
Our services are hosted in data centres that maintain physical access controls, environmental protections, and security monitoring. Physical access to server infrastructure is restricted to authorised personnel. We do not operate our own physical data centre facilities; our hosting providers are selected in part based on their physical security certifications and practices.
11. Employee Security Practices
All Dantrok personnel with access to systems or data receive security awareness training. Staff are required to follow internal security policies covering acceptable use, data handling, and incident reporting. Contractors and partners with system access are subject to equivalent obligations through contractual agreements.
12. Payment Security
Payment transactions processed through our platform are handled by certified payment processors. Dantrok does not store full payment card numbers, card verification codes, or other sensitive cardholder data on its own systems. Payment processing infrastructure complies with applicable industry security standards.
13. Responsible Disclosure
We welcome reports from security researchers and users who identify potential vulnerabilities in our platform. If you believe you have discovered a security issue, please contact us at [email protected] with a description of the issue. We request that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and address it. We will acknowledge receipt of your report and keep you informed of our progress.
14. Policy Review and Updates
This Security Policy is reviewed at least annually and updated as necessary to reflect changes in our practices, technology, or applicable standards. Material changes will be communicated to users through the platform or via email. Continued use of our services following notification of changes constitutes acceptance of the updated policy.
15. Contact
For questions or concerns regarding this Security Policy or our security practices, please contact us:
Dantrok
10 Lyttleton St, East Launceston TAS 7250, Australia
Email: [email protected]
Phone: +61 2 6140 8444