Security Policy
Last updated: 27 March 2025
This Security Policy describes the measures jovuloe takes to protect the confidentiality, integrity, and availability of data processed through our platform at jovuloe.com. By using our services, you acknowledge that you have read and understood this policy.
1. Scope
This policy applies to all systems, infrastructure, applications, and personnel involved in the delivery of jovuloe's online learning platform and associated services. It covers data in transit, data at rest, and all operational processes that handle user information.
2. Data Protection Principles
We process data in accordance with the following core principles:
- Data is collected only to the extent necessary to deliver and improve our services.
- Access to personal and sensitive data is restricted to authorised personnel on a need-to-know basis.
- Data retention periods are defined and enforced; data is securely deleted when no longer required.
- All data handling practices are reviewed periodically to ensure continued appropriateness.
3. Infrastructure Security
3.1 Hosting and Network
Our platform is hosted on infrastructure that meets industry-recognised security standards. Network-level controls include firewalls, intrusion detection mechanisms, and traffic monitoring to identify and respond to anomalous activity.
3.2 Encryption in Transit
All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS). We enforce current recommended protocol versions and cipher suites, and we reject connections that do not meet minimum security requirements.
3.3 Encryption at Rest
Sensitive data stored on our systems is encrypted at rest using industry-standard encryption algorithms. Encryption keys are managed through dedicated key management processes with appropriate access controls and rotation schedules.
3.4 Physical Security
Physical access to data centre facilities used by our infrastructure providers is controlled through multi-factor authentication, surveillance, and staffed security. We select providers who maintain recognised certifications for physical and environmental security.
4. Application Security
4.1 Secure Development Practices
Our development process incorporates security at every stage. This includes threat modelling during design, code review with security considerations, dependency vulnerability scanning, and testing prior to deployment.
4.2 Authentication and Access Control
- User accounts are protected by password hashing using modern, adaptive algorithms.
- Multi-factor authentication is available and encouraged for all user accounts.
- Administrative access requires multi-factor authentication and is granted only to authorised personnel.
- Session tokens are generated securely, have defined expiry periods, and are invalidated upon logout.
4.3 Input Validation and Output Encoding
All user-supplied input is validated and sanitised before processing. Output encoding is applied consistently to prevent injection-based attacks including cross-site scripting and SQL injection.
4.4 Dependency Management
Third-party libraries and components are tracked and monitored for known vulnerabilities. Security patches are applied in a timely manner following a defined patch management process.
5. Access Management
5.1 Principle of Least Privilege
Access rights are assigned based on the minimum permissions required to perform a given function. Elevated privileges are granted temporarily where possible and subject to additional review.
5.2 Employee Access
Staff access to production systems and user data is granted only where operationally necessary. All access is logged and subject to periodic review. Access is revoked promptly upon role change or termination of employment.
5.3 Third-Party Access
Where third-party service providers require access to our systems or data, such access is governed by contractual obligations, limited in scope, and monitored. Providers are assessed for their security posture prior to engagement.
6. Monitoring and Logging
We maintain logs of security-relevant events across our infrastructure and application layers. Logs are stored securely, protected from unauthorised modification, and retained for a defined period to support incident investigation and audit requirements. Automated alerting is configured to detect and notify of suspicious or anomalous activity in a timely manner.
7. Vulnerability Management
7.1 Scanning and Testing
We conduct regular vulnerability scans of our infrastructure and applications. Penetration testing is performed periodically by qualified internal or external parties to identify weaknesses before they can be exploited.
7.2 Responsible Disclosure
We welcome reports of potential security vulnerabilities from researchers and users. If you believe you have identified a security issue affecting our platform, please contact us at:
help@bifixoo.com
Please provide sufficient detail to allow us to reproduce and assess the issue. We commit to acknowledging receipt of your report promptly and to working in good faith to resolve confirmed vulnerabilities. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.
8. Incident Response
We maintain an incident response plan that defines roles, responsibilities, and procedures for identifying, containing, and recovering from security incidents. In the event of a confirmed security incident affecting user data, we will:
- Contain and assess the incident as quickly as practicable.
- Notify affected users and relevant parties as required and in accordance with applicable obligations.
- Conduct a post-incident review to identify root causes and implement corrective measures.
9. Business Continuity and Disaster Recovery
We maintain backup procedures and disaster recovery capabilities to ensure the continued availability of our platform and the recoverability of data in the event of system failure or disruption. Backups are encrypted, stored separately from primary systems, and tested periodically to verify integrity and restorability.
10. Organisational Security
10.1 Security Awareness
All personnel with access to our systems or user data receive security awareness training appropriate to their role. Training covers topics including phishing, safe data handling, and incident reporting procedures.
10.2 Security Policies and Reviews
Internal security policies are documented, communicated to relevant personnel, and reviewed at least annually or following significant changes to our systems or threat landscape.
10.3 Supplier Risk
We assess the security practices of key suppliers and service providers. Contractual requirements for data protection and security are included in agreements with providers who process data on our behalf.
11. User Responsibilities
While we implement extensive controls to protect our platform, users also play an important role in maintaining security. We ask that users:
- Choose strong, unique passwords and do not share account credentials.
- Enable multi-factor authentication where available.
- Log out of sessions on shared or public devices.
- Report any suspected unauthorised access to their account promptly.
- Keep their contact information current to receive security notifications.
12. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When we make material changes, we will update the date at the top of this page and, where appropriate, notify users through the platform or by other means. Continued use of our services following such changes constitutes acceptance of the updated policy.
13. Contact
If you have questions about this Security Policy or wish to report a security concern, please contact us:
| Method | Details |
|---|---|
| help@bifixoo.com | |
| Phone | +353 21 431 7955 |
| Post | 15 Bridge St, Victorian Quarter, Cork, T23 XVF4, Ireland |