Skip to content

Information security policy

This public policy describes our approach to handling information responsibly. It provides a framework for collaboration, solution development and operations.

Version · 1.0 ·

Scope and responsibility

These principles concern SYNEDAT’s work and the handling of customer, employee and business partner information. Management is responsible for the overall direction. Specific tasks and responsibilities are to be defined within the agreed scope of services.

Assess protection needs first

Information should be accessible only to authorised people, protected against unintended changes and available as required. Its type, sensitivity and use determine the level of protection needed. Risks and contractual requirements should be considered early.

Limit access to what is needed

Access rights should reflect tasks and be adjusted when roles change or collaboration ends. Personal accounts, appropriate authentication and careful credential handling support accountable access. Confidential information belongs only in designated systems.

Include security in delivery and operations

Security requirements should inform planning, implementation and handover. Changes should be reviewed, documented and released in a controlled way. Backup, recovery and monitoring should be planned according to protection needs and the agreed operational scope.

Raise concerns early

Potential security issues should be reported promptly to the responsible contact. Investigations should prioritise limiting impact, protecting affected information and coordinated communication. Findings should inform improvements.

Improve together

Secure work needs understandable rules, knowledge sharing and regular review. New requirements, project experience and reported weaknesses should prompt adjustments to practices and measures. Project-specific commitments and responsibilities are agreed separately.

Discuss a security concern

Describe the affected service, what you observed and when. Please do not initially send credentials, personal data sets or confidential evidence. We will agree a suitable channel with you for sensitive details.

[email protected]
Diese Seite teilen
X (Twitter) Facebook LinkedIn E-Mail

Beim Öffnen eines Netzwerks gelten dessen Datenschutzhinweise.

Quick contact