Our security posture
Actigy runs regulated and operationally sensitive work, so security is built into how we deliver. Our practices are GDPR-compliant and aligned with ISO 9001 (quality management) and SOC 2 (security, availability, and confidentiality) control objectives. We describe these as alignment: where a formal certificate or attestation is in place we will say so explicitly, and we support client audits of our controls.
Governance
Security policies are owned by management, reviewed regularly, and communicated to every operator. Access to client data is granted on a need-to-know basis and revoked promptly when no longer required.
People
- Background checks appropriate to the role and jurisdiction before access is granted.
- Confidentiality agreements for all personnel.
- Security and data-protection training at onboarding and on a recurring basis.
- A joiner–mover–leaver process that keeps access matched to current duties.
Access control
Least-privilege, role-based access; unique named accounts; multi-factor authentication on systems that support it; and regular access reviews. Operators work to maker–checker controls and segregation of duties on sensitive workflows.
Data protection
Personal and client data is encrypted in transit (TLS) and at rest. We minimise the data we hold, segregate data by client, and restrict export of client data from approved systems.
Secure delivery model
Wherever possible, our teams work inside your systems and tools rather than copying data into ours. We use managed, hardened endpoints, controlled environments, clean-desk practices, and restrictions on removable media and unmanaged devices.
Monitoring and resilience
We keep access and audit logs on systems handling client data, patch and protect endpoints, and back up critical systems. Our follow-the-sun footprint across Bulgaria, Romania, Poland, and Ukraine provides geographic and operational resilience.
Sub-processors and vendors
We vet the providers we rely on, bind them to confidentiality and data-protection terms, and maintain a current list of sub-processors that is available to clients on request. See our Data Processing terms.
Incident response
We maintain an incident-response process. If a personal-data breach affects a client, we notify the affected client without undue delay and support their obligations under the GDPR.
Responsible disclosure
If you believe you have found a security issue, please contact hello@actigy.com. Our disclosure contact is also published at /.well-known/security.txt. We ask that you give us a reasonable opportunity to remediate before any public disclosure.
Questions about this policy? Email hello@actigy.com.