Legal
Security Policy
In effect from 1 May 2025
Introduction
Effective Date: 01-05-2025
At Wastify AI Ltd (“Wastify”, “we”, “our”, “us”), security is fundamental to everything we do. Our clients rely on us to safeguard sensitive building, tenant, and ESG data, and we are committed to maintaining the highest standards of information security, confidentiality, and integrity.
This Security Policy outlines the technical and organisational measures we implement to protect data across our platform, infrastructure, and business operations.
Security Principles
We operate under the following guiding principles:
- Confidentiality – Data is accessible only to authorised individuals.
- Integrity – Data is accurate, consistent, and protected against unauthorised changes.
- Availability – Services remain secure, reliable, and accessible when needed.
Technical Security Controls
- EncryptionAll data is encrypted in transit using TLS 1.2+.
- All data is encrypted at rest using AES-256 industry standards.
- Encryption keys are managed securely within UK/EU cloud infrastructure.
- Access ControlsRole-based access control (RBAC) is enforced across systems.
- Multi-factor authentication (MFA) is mandatory for administrators.
- Principle of least privilege applied to all employees and contractors.
- Network SecurityServices are hosted in ISO 27001-certified data centres within the UK/EU.
- Firewalls, intrusion detection, and anomaly monitoring are applied.
- Segregated environments are maintained for development, testing, and production.
- Monitoring & LoggingContinuous monitoring of infrastructure, applications, and endpoints.
- Detailed audit logs maintained for all data access and changes.
- Automated alerts for suspicious activity.
Organisational Security Controls
- Employee Training: All staff receive annual information security and GDPR training.
- Background Checks: Employees with system access undergo pre-employment checks.
- Policies & Procedures: Acceptable use, incident response, and data handling policies are mandatory.
- Third-Party Management: Vendors and partners must sign data processing agreements and demonstrate compliance with security standards.
Incident Response
- Wastify maintains a formal Incident Response Plan.
- All incidents are logged, categorised, and investigated promptly.
- The Data Protection Officer (DPO) oversees incident management.
- Clients and regulators (ICO) will be notified within 72 hours if a breach results in a risk to data subjects.
Business Continuity & Disaster Recovery
- Data backups are performed daily, with geo-redundancy.
- Disaster recovery plans are tested regularly to ensure service continuity.
- Recovery point objectives (RPO) and recovery time objectives (RTO) are aligned to enterprise standards.
Compliance & Auditing
- Wastify conducts regular internal security audits.
- External penetration testing is carried out to identify and address vulnerabilities.
Policy Governance
- Owner: Data Protection Officer (DPO), Wastify AI Ltd.
- Review: This policy is reviewed annually, or sooner if regulations or practices change.
- Enforcement: Employees, contractors, and partners are bound to comply. Non-compliance may result in disciplinary or contractual action.
Contact
For questions or concerns about this Security Policy, please contact:
📧 hello@wastify-ai.co.uk