ISTROLABEISTROLABE
ISO 27001 & SOC 2 Standards

Information Security Policy

Last updated: August 2026

1. Information Security Governance Information security is foundational to ISTROLABE's software engineering services. We enforce security best practices aligned with ISO 27001 and SOC 2 Type II trust principles to protect client intellectual property, proprietary source code, and enterprise data.

2. Security Controls & Architecture - **Access Control & Least Privilege:** Role-based access control (RBAC), multi-factor authentication (MFA), and mandatory session timeouts across all development and administrative systems. - **Cryptographic Protections:** Enforced TLS 1.3 encryption for data in transit and AES-256 encryption for data at rest. - **Vulnerability Management:** Continuous dependency scanning, static code analysis (SAST), and annual third-party penetration tests. - **Environment Isolation:** Complete separation between development, staging, and production environments, with zero production data utilized in test environments.

3. Incident Management & Disaster Recovery We maintain a 24/7 Security Incident Response Plan with defined severity levels, notification windows, and disaster recovery procedures guaranteeing minimal Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO).