Legal
Security Policy
- Effective date
- Last reviewed
HCT SYSTEMS JSC builds systems that other organisations depend on, and we are often trusted with their data. This policy states how we protect information — ours and theirs — and what we hold ourselves accountable for.
1. Purpose and scope
This policy applies to every director, employee, contractor and supplier of HCT Systems, and to all information assets we own or handle: client data, source code, credentials, business records, and the systems they live on.
It is structured around the ISO/IEC 27001 control themes. We are not certified today; we say so plainly rather than implying otherwise, and we design controls so that certification is achievable without redesigning how we work.
2. Principles
- Least privilege. Access is granted for a stated reason, at the smallest scope that works, and removed when no longer needed.
- Defence in depth. No single control is assumed to hold. A failure at one layer should be contained by the next.
- Secure by default. New systems start locked down. Access is opened deliberately, not closed retroactively.
- Evidence over assertion. A control that cannot be demonstrated is treated as absent.
- Honest disclosure. If we get something wrong, affected parties hear it from us, promptly.
3. Governance
- Management is accountable for information security and reviews this policy at least annually.
- A named Security Officer owns day-to-day implementation, incident coordination and risk register upkeep.
- Risks are recorded with an owner, an assessed impact and likelihood, and a treatment decision. Accepted risks are accepted explicitly, by a person, with a date.
4. People
- Confidentiality obligations are contractual and survive the end of the engagement.
- Access rights are provisioned on joining, reviewed on role change, and revoked on the last working day.
- Everyone receives security awareness training on joining and periodically thereafter, covering phishing, credential handling and secure development.
5. Access control
- Multi-factor authentication is mandatory on every system that holds client data, source code or credentials.
- Shared accounts are not used. Where a system does not support individual accounts, access is brokered and logged.
- Secrets are held in a managed secret store. Credentials are never committed to source control; repositories are scanned for accidental disclosure and any exposed credential is treated as compromised and rotated.
- Privileged access is reviewed at least quarterly.
6. Data protection
- In transit: TLS 1.2 or above, with modern cipher suites, for all connections carrying non-public data.
- At rest: full-disk encryption on all endpoints; encryption at rest for managed storage services.
- Minimisation: we ask clients for the least data that lets us do the work, and prefer synthetic or anonymised data in development and test environments.
- Disposal: data is deleted at the end of the retention period defined in the relevant agreement, and endpoints are cryptographically wiped before disposal or reassignment.
7. Secure development
Security is part of the development lifecycle described in our AI-DLC approach, not a gate at the end of it.
- Threat modelling for new systems and for changes that alter a trust boundary.
- Mandatory peer review before merge. Code produced with AI assistance is reviewed to the same standard as code typed by hand — the review is the control, and the origin of the code does not change it.
- Automated static analysis and dependency vulnerability scanning in continuous integration; builds fail on findings above the agreed severity.
- Separated development, staging and production environments, with no production data in lower environments.
- Infrastructure defined as code and peer-reviewed on the same terms as application code.
8. Operations
- Centralised logging with tamper-evident retention for systems handling client data.
- Monitoring and alerting on availability, error rates and security-relevant events.
- Patching on a risk-based schedule; critical vulnerabilities in internet-facing systems are remediated urgently.
- Backups taken according to the recovery objectives agreed with the client, encrypted, and restore-tested — an untested backup is not a backup.
9. Supplier security
Before a supplier handles data on our behalf, we assess their security posture and put a written agreement in place covering confidentiality, security measures, sub-processing, breach notification and deletion on termination. Suppliers are reassessed periodically.
10. Incident response
We maintain a documented incident response process covering detection, containment, eradication, recovery and post-incident review.
- Incidents are triaged by severity and coordinated by the Security Officer.
- Affected clients are notified without undue delay, with what we know, what we do not yet know, and what we are doing.
- Where a personal data breach is notifiable, we notify the relevant supervisory authority within the statutory deadline — 72 hours under GDPR — and affected individuals where required.
- Every significant incident gets a written post-incident review focused on the contributing conditions rather than on individual blame.
11. Business continuity
Critical systems are identified with recovery time and recovery point objectives. Recovery procedures are documented and exercised.
12. Reporting a vulnerability
If you believe you have found a security issue in our systems or in this website, please tell us at security@hct-systems.com.
- Give us enough detail to reproduce the issue.
- Please do not access, modify or delete data belonging to others, degrade our services, or run automated scanning that affects availability.
- We will acknowledge within 3 business days, keep you updated, and credit you if you would like that.
We will not pursue legal action against researchers who report in good faith and follow the guidance above.
13. Compliance and review
This policy is reviewed at least annually and whenever a significant change to our systems, services or legal obligations occurs. Breaches of it are handled through our disciplinary process.
14. Contact
HCT SYSTEMS JSC — Security Officer security@hct-systems.com 237A/08 Dũng Sĩ Thanh Khê, Phường Thanh Khê, Thành phố Đà Nẵng, Viet Nam