SECURITY POLICY
Security is
by design.
At Consulaw Technologies, security is not an afterthought — it is a foundational principle embedded into every system we build and every process we follow.
ISO 27001-Aligned
Defence-in-Depth
Continuous Monitoring
Regular Audits
This Security Policy describes how Consulaw Technologies protects client data, internal systems, and the software products we deliver. Our security programme is aligned with ISO 27001 principles and the Nigeria Data Protection Act 2023. We continuously evolve our controls to address emerging threats.
Infrastructure Security
- All production systems are hosted on enterprise-grade cloud infrastructure with SOC 2 Type II certified providers.
- Network access is enforced through firewalls, VPNs, and least-privilege access controls at every layer.
- Data at rest is encrypted using AES-256. Data in transit is protected by TLS 1.2 or higher at all endpoints.
- Infrastructure configurations are managed as code and reviewed prior to deployment to production.
Access Control
- Access to client data and internal systems is granted on a strict need-to-know basis.
- Multi-factor authentication (MFA) is enforced for all internal systems and administrative interfaces.
- Access permissions are reviewed quarterly and revoked immediately upon role change or offboarding.
- Privileged access sessions are logged, monitored, and subject to periodic review.
Secure Development
- Our engineering team follows OWASP Secure Coding Guidelines throughout the software development lifecycle.
- All code changes undergo peer review and automated security scanning before merging to production branches.
- Third-party dependencies are tracked using software composition analysis (SCA) tools and updated regularly.
- Critical security patches are prioritised and deployed within 48 hours of release.
Data Protection
- Client data is logically separated per engagement. No client data is shared between unrelated accounts.
- Production databases are backed up daily with encrypted off-site storage and tested restoration procedures.
- Personal data handling complies with the Nigeria Data Protection Act 2023 (NDPA) and applicable international frameworks.
- Data retention schedules are enforced, and data is securely destroyed at the end of its retention period.
Incident Response
- We maintain a documented Incident Response Plan covering detection, containment, eradication, and recovery.
- Security incidents are triaged by severity. Critical incidents are escalated to leadership within 1 hour of detection.
- Affected clients are notified of material security incidents as soon as is practicable and no later than 72 hours.
- Post-incident reviews are conducted to identify root causes and implement corrective measures.
Vulnerability Disclosure
- We welcome responsible disclosure of security vulnerabilities from security researchers and clients.
- Please report potential vulnerabilities to security@consulawtech.com with a detailed description.
- We acknowledge all reports within 5 business days and provide an initial assessment within 10 business days.
- We do not take legal action against researchers who act in good faith and follow our disclosure guidelines.
Security Awareness
- All team members complete mandatory security awareness training upon joining and annually thereafter.
- Phishing simulation exercises are conducted regularly to maintain vigilance across the organisation.
- Our engineering team receives role-specific security training covering secure coding and threat modelling.
- Security policies are reviewed annually and updated to reflect the current threat landscape.
Compliance & Audits
- We align our security programme with ISO 27001 information security management principles.
- Internal security audits are conducted quarterly. External penetration tests are conducted annually.
- Audit findings are tracked to remediation with defined owners and deadlines.
- Clients may request our security documentation under NDA as part of vendor due diligence.
Report a Vulnerability
Found a security issue? We take all reports seriously. Responsible disclosure helps us protect our clients and improve our systems.
security@consulawtech.comPlease include: affected system, description of the vulnerability, steps to reproduce, and your contact details.
Subscribe to Intelligence
Receive weekly insights on AI, digital transformation, automation, and technology strategy.