Security and privacy policies
These are controlled public summaries. Restricted operating procedures, detailed architecture, full incident playbooks, test findings, access rosters, and raw evidence are not published. Approved material is shared according to its disclosure classification.
Information Security Programme Summary
How WiBiz governs security, assigns ownership, manages risk, and distinguishes policy from operating evidence.
Data Protection and Privacy Summary
Our public commitments for lawful handling, data minimisation, rights requests, retention, transfers, and client-specific processing terms.
Access Control and Identity Summary
Least privilege, named access, authentication, review, offboarding, service identities, and evidence requirements.
Encryption and Key Management Summary
Required protection for data in transit and at rest, plus the build-specific evidence needed before a control claim is made.
Incident Response Summary
How security events are triaged, contained, investigated, communicated, recovered, and closed.
Business Continuity and Recovery Summary
Continuity planning, dependency assessment, backup and restore evidence, and service-specific recovery commitments.
Vendor and Subprocessor Management Summary
Risk-based supplier review, contractual controls, subprocessor transparency, material-change review, and evidence limitations.
Secure Change and Vulnerability Management Summary
Security design, release evidence, vulnerability handling, independent testing, remediation, and retest requirements.
Data Retention and Disposal Summary
How retention, return, deletion, backup handling, legal holds, and deletion evidence are set for each service.
Vulnerability Disclosure Policy
How to report a suspected vulnerability safely, what testing is permitted, and how coordinated disclosure works.
Product terms, data-processing terms, service levels, security schedules, independent test material, and client-specific annexes have separate approval and disclosure controls. Contact us for the documents applicable to an assessed service.