Security Policy

Our commitments and controls around information security, responsible disclosure, and incident response — across SSDB Tech's engineering, consulting, and managed services engagements and this website.

Last updated: 26 July 2026

Scope of this Policy. This Security Policy applies to SSDB Tech Services, Inc.'s corporate systems, delivery infrastructure, and ssdbtech.com. Our Core AI platform at core.ssdbtech.com maintains its own security documentation covering product-specific controls, tenant isolation, model handling, and sub-processor governance. Where an engagement involves both services and Core, additional product-specific terms apply.

Security is engineered into every layer of what we build and deliver. This Policy describes the technical, administrative, and physical safeguards SSDB Tech Services, Inc. maintains — and how to report a vulnerability if you find one.

1. Security principles

Our security program is guided by five principles:

  • Zero-trust by default. No implicit trust based on network location. Every request is authenticated, authorized, and logged.
  • Least privilege. Access to systems and data is granted only to those with a demonstrated business need, and only to the minimum extent required.
  • Defense in depth. Multiple, overlapping controls at network, application, and data layers.
  • Compliance by design. Security and privacy controls are engineered into specifications from the outset, not retrofitted at release.
  • Continuous verification. Security posture is measured, tested, and improved on a continuous basis — not a point-in-time exercise.

2. Compliance alignment

Our security controls and operational practices align with the following industry frameworks and regulations, applied according to the context of each engagement:

SOC 2ISO 27001HIPAAGDPRCCPAIEC 42001NIST CSF 2.0

Current certification status, audit scope, testing dates, and third-party attestation reports are available under a mutual non-disclosure agreement as part of formal enterprise due diligence. Requests should be directed to legal@ssdbtech.com.

3. Technical controls

Encryption. All data in transit is protected using TLS 1.2 or higher. Data at rest is encrypted using AES-256 or equivalent. Encryption keys are managed through hardened key management services with strict access controls and defined rotation policies.

Access & identity. Multi-factor authentication is required for all administrative and production access. Identity is federated through enterprise identity providers with role-based access controls, just-in-time privilege elevation, and full audit logging.

Network security. Production environments are logically segmented from corporate networks. Traffic is filtered at multiple layers (WAF, IDS/IPS, egress controls). Public endpoints are protected against common attack vectors including the OWASP Top 10, DDoS, and credential-stuffing.

Vulnerability management. We perform continuous vulnerability scanning of infrastructure and applications, dependency scanning of code, and static analysis in every CI pipeline. Vulnerabilities are triaged and remediated on defined SLAs proportional to severity.

Penetration testing. Independent third-party penetration tests are conducted at least annually, and more frequently for material changes. Findings are tracked to closure with executive-level visibility.

Logging & monitoring. Production systems generate structured, tamper-evident logs shipped to a centralized SIEM. Security events are triaged by our security function with defined escalation paths.

4. Administrative controls

Personnel security. All employees and contractors undergo background checks (where lawful in the applicable jurisdiction) and sign confidentiality agreements. Security awareness training is mandatory at onboarding and annually thereafter.

Change management. Production changes follow a peer-reviewed pull-request workflow with automated testing, code scanning, and approval gates. Emergency changes are documented and reviewed post-hoc.

Sub-processor and vendor management. Third-party service providers are assessed for security posture before onboarding, bound contractually to security and privacy obligations, and periodically re-reviewed. A current list of our material sub-processors is available on written request.

Data classification. Data is classified by sensitivity, with handling requirements defined for each tier. Client data is isolated and handled according to the contractual terms of each engagement and applicable Data Processing Addendum.

5. Incident response

SSDB Tech maintains a documented incident response plan covering identification, containment, eradication, recovery, and post-incident review. Our incident response function operates with defined escalation paths, communication plans, and forensic procedures.

Client notification. Where an incident materially affects a client's data or services, we notify affected clients without undue delay and within the timeframes required by contract and applicable law — including within 72 hours of becoming aware of a personal data breach where GDPR applies, and equivalent obligations under HIPAA, state breach notification laws, and other applicable regimes.

Post-incident review. Every material incident is followed by a blameless post-mortem, with corrective actions tracked to closure and material findings summarized for affected clients where appropriate.

6. Business continuity and resilience

Critical systems are engineered for high availability with automated failover, geographically distributed backups, and documented recovery procedures. Recovery time objectives (RTO) and recovery point objectives (RPO) are defined per system and tested at least annually.

7. Responsible disclosure

We welcome reports of potential security vulnerabilities from the security research community. If you believe you have discovered a vulnerability in ssdbtech.com or any SSDB Tech corporate system, please report it to us so we can investigate and remediate.

For vulnerabilities in the Core product, please report through the channel listed at core.ssdbtech.com.

How to report a vulnerability

Send a report by email to security@ssdbtech.com. Please include:

  • A clear description of the vulnerability and the affected component.
  • Reproduction steps or a proof of concept.
  • Any suggested remediation, if you have one.
  • Contact information so we can follow up.

Our commitment to you. We will acknowledge your report within three business days, work with you to validate the finding, remediate on a timeline commensurate with severity, and credit you (with your consent) once the vulnerability is resolved.

Safe-harbor for good-faith research. Research conducted in good faith and in accordance with this Policy will not result in legal action from SSDB Tech. We will not initiate a lawsuit or law-enforcement referral against you for research activities that comply with this Policy.

Please do not: access, modify, or destroy data that does not belong to you; degrade our services (denial-of-service, brute-force, resource exhaustion); phish or socially engineer our staff, clients, or partners; violate the privacy of our personnel or clients; or publicly disclose a vulnerability before we have had reasonable time to remediate and coordinate disclosure with you.

8. Governance

The SSDB Tech security program is owned by executive leadership, with day-to-day operations run by a dedicated security function. Security posture, incidents, and program maturity are reviewed on a defined cadence with executive stakeholders.

9. Contact

SSDB Tech Services, Inc.

Security reports (vulnerabilities, incidents): security@ssdbtech.com

Legal and compliance inquiries: legal@ssdbtech.com

General inquiries: contact@ssdbtech.com