Abstra

    Information Security Policy

    Last updated March 31st, 2025
    Document owner: CTO

    1. PURPOSE AND SCOPE

    This Information Security Policy (hereinafter "Policy") is hereby established for the purpose of protecting the information assets of Abstra and customer data, ensuring compliance with applicable data protection laws and regulations. The provisions of this Policy shall be binding upon all employees, contractors, and third parties granted access to Abstra systems.

    2. SYSTEM SECURITY PRINCIPLES

    The following core security principles shall be maintained across all Abstra systems and operations:

    • Secure communication and data transmission using industry-standard encryption protocols;
    • Access control and authentication implementing the principle of least privilege;
    • Data protection and privacy in accordance with applicable regulations;
    • System isolation and segmentation to prevent unauthorized lateral movement;
    • Security monitoring and logging of all relevant system activities; and
    • Compliance with applicable regulations and industry standards.

    3. DEFINITIONS AND COVERAGE

    3.1. Applicability

    This Policy applies to all Abstra systems, including but not limited to:

    • Cloud infrastructure and associated services;
    • Customer data stored or processed by Abstra systems;
    • Internal systems used for business operations;
    • Development environments containing source code or proprietary information;
    • Third-party services integrated with Abstra systems; and
    • Personal data as defined by applicable data protection regulations.

    3.2. Legal Compliance

    Abstra shall maintain compliance with applicable regulations through the following measures:

    • Data protection compliance shall be mandatory for all data processing activities;
    • Data subject rights shall be respected and fulfilled within prescribed timeframes;
    • Data protection impact assessments shall be conducted as required by regulation;
    • Records of processing activities shall be maintained in accordance with legal requirements; and
    • Data Protection Officer (DPO) responsibilities shall be fulfilled by the CTO or their designee within the engineering team.

    4. DATA PROTECTION AND SECURITY

    4.1. Data Storage Requirements

    Abstra shall implement the following data storage requirements:

    • Data shall be stored in accordance with applicable data protection requirements;
    • Data localization requirements shall be respected for regulated data types;
    • Cross-border data transfers shall comply with applicable regulations and safeguards;
    • Data retention periods shall be defined and documented for different data categories; and
    • Data minimization principles shall be applied to limit collection to necessary information.

    4.2. Encryption Requirements

    The following encryption requirements shall be implemented for all systems:

    • Data in transit shall be encrypted using TLS 1.3 or subsequent versions;
    • Data at rest shall be encrypted using AES-256 or equivalent algorithms;
    • Encryption keys shall be managed securely through a formal key management system;
    • Key rotation shall be performed at least annually, with automated weekly rotation implemented for production encryption keys and immediate rotation upon detection of potential compromise; and
    • Cryptographic controls shall be reviewed and updated as encryption standards evolve.

    4.3. Data Storage and Processing Responsibilities

    4.3.1. User-Managed Data

    The following provisions apply to user-managed data:

    • Abstra provides a platform where customers can deploy their applications;
    • Abstra shall not control the nature of data stored by customers on the platform;
    • Users are responsible for securing their application data through appropriate controls;
    • Users are responsible for managing access to their resources according to their security requirements;
    • Users are responsible for protecting sensitive information through encryption and access controls;
    • Users are responsible for implementing appropriate security measures for their applications; and
    • Users are responsible for ensuring compliance with applicable data protection regulations.

    4.3.2. Abstra-Managed Data

    Abstra shall protect managed data through the following controls:

    • Data encryption at rest shall be implemented for all secrets and sensitive data;
    • Data encryption in transit shall be implemented for all communications containing sensitive data;
    • Data classification shall be implemented for different sensitivity levels;
    • Data retention and disposal policies shall be strictly enforced; and
    • Access to sensitive data shall be limited to authorized personnel with legitimate business need.

    5. MONITORING AND INCIDENT RESPONSE

    5.1. Continuous Monitoring

    Security monitoring shall include the following components:

    • Security monitoring shall be continuous and automated where technically feasible;
    • Log collection shall be centralized in a secure, tamper-resistant repository;
    • Alert thresholds shall be defined based on risk assessment and threat intelligence;
    • Incident detection shall be automated through correlation and pattern recognition; and
    • Data breach detection shall be prioritized through specialized monitoring controls.

    5.2. Incident Response

    Incident response processes shall include the following elements:

    • Incident response plan shall be maintained and tested at least annually;
    • Data breach procedures shall be documented with clear roles and responsibilities;
    • Customer notification procedures shall be defined in accordance with contractual obligations;
    • Regulatory reporting shall be timely and complete as required by applicable regulations; and
    • Incident documentation shall be maintained for lessons learned and compliance purposes.

    6. COMPLIANCE AND TRAINING

    6.1. Security Culture

    The security awareness program shall include the following components:

    • Security awareness program shall be mandatory for all personnel;
    • Data protection training shall be provided annually to all staff members;
    • Role-specific training shall be conducted for engineering team members with security responsibilities;
    • Training completion shall be tracked and documented for compliance purposes; and
    • Security awareness materials shall be updated to address emerging threats.

    6.2. Audit Requirements

    The following audit requirements shall be implemented:

    • Security architecture reviews shall be conducted every six (6) months by the CTO and engineering team;
    • Third-party security assessments shall be conducted annually by qualified assessors;
    • Data protection compliance audits shall be conducted according to regulatory requirements;
    • Annual policy and procedure reviews shall be performed by the CTO; and
    • Audit findings shall be remediated according to defined timeframes based on risk.

    7. POLICY MAINTENANCE

    This Policy shall be subject to periodic review to ensure compliance with information security best practices and applicable laws and regulations.

    • Annual policy review shall be conducted by the CTO;
    • Updates shall be made in response to regulatory changes affecting security requirements;
    • Updates shall be made based on incident analysis and identified control deficiencies;
    • Updates shall be made to reflect technological changes affecting security posture; and
    • Policy effectiveness shall be measured through security metrics and compliance assessments.

    8. DEFINITIONS

    • DPO: Data Protection Officer.

    9. ROLES AND RESPONSIBILITIES

    9.1. CTO Responsibilities

    The CTO shall be responsible for:

    • Overall ownership and enforcement of this Policy;
    • Final approval of security architecture and controls;
    • Assignment of security responsibilities within the engineering team;
    • Serving as or appointing a designated Data Protection Officer when required;
    • Review and approval of exceptions to this Policy; and
    • Reporting security status to executive leadership.

    9.2. Engineering Team Responsibilities

    The engineering team shall be responsible for:

    • Implementation of security controls as specified in this Policy;
    • Day-to-day security operations and monitoring;
    • Security incident detection, response, and remediation;
    • Security testing and vulnerability management;
    • Development and maintenance of secure systems; and
    • Providing input for security policy updates based on operational experience.

    CONTACT AND DOCUMENTATION REQUESTS

    For questions about this Policy, or to request our full security documentation package (supporting policies, control evidence, and our latest third-party penetration test report), contact us at help@abstra.app