1. Security principles#
- Security by design throughout the development lifecycle.
- Least-privilege access to systems and customer data.
- Continuous monitoring and operational visibility.
- Commercially reasonable administrative, technical and organisational safeguards.
2. Infrastructure#
- Cloud-hosted architecture using trusted infrastructure providers.
- Production systems separated from development environments where practical.
- Infrastructure changes managed through controlled deployment processes.
3. Authentication and access control#
- Individual named user accounts.
- Role-based permissions within organisations and workspaces.
- Support for Single Sign-On (where purchased and available).
- Administrative access restricted to authorised personnel.
- Multi-factor authentication encouraged and used for privileged accounts where available.
4. Encryption#
- Encryption in transit using TLS.
- Encryption at rest where supported by underlying infrastructure.
- Secrets and credentials stored using secure management practices.
5. Customer data protection#
- Customers retain ownership of Customer Data.
- Customer Data is processed only to provide, secure and support the Services.
- Access to Customer Data is limited to authorised personnel with a legitimate business need.
6. Logging and monitoring#
- Security and operational events are logged.
- Monitoring is used to detect availability, reliability and security issues.
- Logs are retained in accordance with operational requirements and applicable law.
7. Backup and business continuity#
- Regular backups of production data where appropriate.
- Documented recovery procedures.
- Recovery capabilities are periodically reviewed and improved.
8. Vulnerability management#
- Security updates applied on a risk-based basis.
- Dependencies are maintained and updated where practical.
- Identified vulnerabilities are prioritised according to severity.
9. Incident response#
- Documented incident response process.
- Security incidents are investigated and remediated.
- Customers are notified of qualifying personal data breaches in accordance with the Subscription Terms and applicable law.
10. Subprocessors#
- TopMod uses carefully selected service providers to deliver the Services.
- Subprocessors are subject to contractual confidentiality and data protection obligations.
- A current list of subprocessors is available upon request or via the TopMod website.
11. Customer responsibilities#
- Maintain strong passwords and account security.
- Manage user permissions appropriately.
- Ensure lawful use of the Services and compliance with internal policies.
- Notify TopMod promptly of suspected security incidents affecting Customer accounts.
12. Security roadmap#
- TopMod continually enhances its security programme.
- Security controls, certifications and platform capabilities may evolve as the Services mature.
13. Contact#
Security enquiries: legal@topmod.dev
Responsible disclosure enquiries: legal@topmod.dev
Important notice#
This document provides a high-level overview of TopMod's security practices. It is not a warranty, service level agreement or contractual commitment unless expressly incorporated into a Subscription Order.