LEGAL-004
TailorDrive Security Policy
Status: Draft
Version: 0.1.0
Document ID: LEGAL-004
In short
Information security is an essential part of the TailorDrive service.
This policy describes the general measures we implement to protect data, user accounts and service operation. It does not describe the technical implementation in detail and does not disclose information that could reduce platform security.
1. Purpose of this document
This policy explains how TailorDrive protects information processed through the service.
It supplements:
- LEGAL-001 - Privacy Policy;
- LEGAL-003 - Data Retention and Deletion Policy;
- LEGAL-005 - Service Level Agreement (SLA).
2. Scope
This policy applies to:
- the TailorDrive website;
- the web application;
- the TailorDrive Client desktop application;
- backend services required for platform operation.
3. Our principles
When designing and developing TailorDrive, we follow these principles:
- access to data is limited to authorized persons;
- only data necessary to provide the service is processed;
- communications are protected through secure connections;
- incidents are analyzed and handled within a reasonable time;
- security measures are reviewed periodically.
4. User authentication
Access to TailorDrive is based on a user account.
Currently:
- authentication uses e-mail address and password;
- passwords are not stored in plain text;
- passwords are stored only as cryptographic hashes;
- users are responsible for keeping their credentials confidential.
5. Data protection
TailorDrive applies technical and organizational measures to protect data.
As of this version:
- uploaded files are encrypted before storage;
- passwords cannot be recovered in the form entered by the user;
- access to data is controlled through authentication and authorization mechanisms;
- communications between applications and the server use secure connections.
Other data categories are protected through platform security mechanisms and are not individually encrypted at field level.
6. Uploaded files
TailorDrive allows documents and other files to be uploaded.
Files are stored in encrypted format and can be accessed only through the application's authorization mechanisms.
7. Logging and audit
For operation and security, technical information may be recorded, such as:
- logins;
- relevant accesses;
- security events;
- administrative operations;
- other events required for incident diagnosis.
This information is used only for administration and security of the service.
8. Security updates
TailorDrive is developed and maintained so identified vulnerabilities can be remediated through application and infrastructure updates.
9. User responsibility
Each user is responsible for:
- using sufficiently strong passwords;
- keeping authentication data confidential;
- using the application according to the Terms and Conditions;
- reporting suspicious activity observed in their account.
10. Limitations of this policy
For security reasons, this policy does not describe the application architecture, algorithms used or internal protection procedures in detail.
Publishing such information could reduce the effectiveness of implemented security measures.
11. Changes to this policy
This policy may be updated to reflect legal, technical or operational changes.
The updated version will be published on the website and in the TailorDrive application.
