Information Security Policy
Last updated: 17 September 2026. Public summary of our internal policy, version 1.0 of 17 August 2026, approved by the administrator.
Status, stated exactly
DEVALAND MARKETING S.R.L. runs an information security management system documented to ISO/IEC 27001:2022, in operation since August 2026: policies, risk assessment, a Statement of Applicability, incident and restore-test registers, and objectives measured every month.
We are going through certification with a certification body. Stage 1 of the audit was completed in August 2026. We are not yet ISO/IEC 27001 certified. When the certificate is issued, it will be published on this page as a document, not as a badge.
Principles
- Least privilege. Access is granted only as far as a task strictly needs, and only for as long as it needs it.
- Your material stays inside the agreed perimeter. It is not published, not committed to code repositories and not passed to third parties without a contractual basis.
- Secrets do not live in code. Passwords and keys are kept separately with restrictive permissions, and their exclusion from repositories is checked automatically.
- Nothing travels unencrypted. Every channel we use is encrypted in transit.
- A backup that has never been restored is not a backup. Restores are tested periodically and recorded.
- Verify before asserting. The state of a system is established by querying the system, not from memory. An empty result is not proof of compliance.
- Automation instead of discipline wherever possible. We are a small firm, and an automated check that cannot be skipped is safer than a rule that depends on attention.
Mandatory rules
- Accounts: one account per person, no shared accounts, two-step login wherever the provider offers it.
- Credentials: platform credentials are never given to a third party. A request for access to our accounts is refused and recorded as a security event.
- Client data: kept in locations only the administrator can access, and deleted at the agreed date.
- Development: separate development, test and production environments. Development and testing use synthetic data only.
- Delivery: nothing goes to production without passing tests. Every change is versioned and reversible.
- Legal documents: signed with a qualified electronic signature.
- Incidents: every suspicious event is recorded and assessed, even when it turns out to have no consequence.
What it means for you
- Our production servers are hosted in the European Union, in France.
- Personal data we process on your behalf is covered by our Data Processing Agreement (GDPR Article 28), which also lists sub-processors and breach notification.
- We deliver remotely and do not ask for access to your accounts beyond what a piece of work strictly needs, for a limited time.
- For a procurement or a contract, the Statement of Applicability and the relevant policies are available on request.
Who is responsible
Ion-Marius Andronie, administrator and sole shareholder, holds the roles of management representative for information security and data protection officer. The combination of roles is documented and assumed. External collaborators, when involved, get project-limited access for a fixed period after signing a confidentiality agreement.
Report a security concern to office@devaland.com. The policy is reviewed at least once a year and after any significant change or incident.
Romanian version: devaland.cloud/securitatea-informatiei.html