Security Policy
Last updated: October 5, 2025
HuskDrevos is committed to protecting the security of its platform, systems, and the data entrusted to us by learners and educators worldwide. This Security Policy describes the measures we take to safeguard information, the responsibilities of all parties, and the procedures in place for identifying and responding to security incidents.
1. Scope
This policy applies to all systems, infrastructure, applications, and data operated or managed by HuskDrevos, including the huskdrevos.com platform and any associated services. It covers all users, employees, contractors, and third-party service providers who access or interact with our systems.
2. Data Protection Principles
We handle all personal and account data according to the following core principles:
| Principle | Description |
|---|---|
| Confidentiality | Data is accessible only to authorized individuals and systems. |
| Integrity | Data is accurate, complete, and protected against unauthorized modification. |
| Availability | Systems and data remain accessible to authorized users when needed. |
| Minimization | Only data necessary for the stated purpose is collected and retained. |
| Accountability | All access and changes to sensitive data are logged and auditable. |
3. Infrastructure Security
3.1 Network Controls
Our infrastructure is protected by multi-layered network security controls, including firewalls, intrusion detection systems, and traffic filtering. Access to internal systems is restricted by role and enforced through strict network segmentation.
3.2 Encryption
All data transmitted between users and our platform is encrypted using industry-standard TLS protocols. Sensitive data stored at rest is encrypted using strong, widely accepted encryption standards. Encryption keys are managed through dedicated key management procedures and rotated on a regular schedule.
3.3 Server and Hosting Security
Our servers operate in access-controlled environments. Operating systems and software dependencies are kept up to date with security patches applied on a documented schedule. Unnecessary services and open ports are disabled by default.
4. Access Control
4.1 Authentication
All accounts on the HuskDrevos platform require secure authentication. We support and encourage the use of strong, unique passwords. Administrative and privileged access requires multi-factor authentication. Session tokens are time-limited and invalidated upon logout or detected anomalous activity.
4.2 Principle of Least Privilege
Access to systems, data, and administrative tools is granted only to the extent required for a given role or task. Access rights are reviewed periodically and revoked promptly when no longer needed.
4.3 Third-Party Access
Third-party vendors and service providers who require access to our systems are subject to security review prior to engagement. Their access is scoped, time-limited, and monitored. We require that third parties maintain security standards consistent with this policy.
5. Application Security
5.1 Secure Development Practices
Security is integrated into our software development lifecycle. Code changes undergo review processes that include security considerations. We follow established guidelines for preventing common vulnerabilities including injection attacks, cross-site scripting, cross-site request forgery, and insecure direct object references.
5.2 Dependency Management
Third-party libraries and software components used within our platform are inventoried and monitored for known vulnerabilities. Affected components are updated or replaced in a timely manner upon disclosure of security issues.
5.3 Security Testing
We conduct regular security assessments of our platform, including vulnerability scanning and periodic penetration testing. Findings are triaged by severity and remediated according to documented timelines.
6. Monitoring and Logging
Our systems generate logs of authentication events, administrative actions, and significant system activity. Logs are stored securely, protected against unauthorized modification, and retained for a period sufficient to support security investigations. Automated monitoring tools alert our team to anomalous patterns or potential threats in real time.
7. Incident Response
7.1 Detection and Triage
We maintain procedures for detecting, classifying, and escalating potential security incidents. Upon detection of a suspected incident, our team initiates an assessment to determine scope, impact, and appropriate response actions.
7.2 Containment and Recovery
Confirmed incidents are contained as quickly as practicable to limit impact. Affected systems are isolated, investigated, and restored from verified clean states where necessary. Root cause analysis is conducted following resolution to prevent recurrence.
7.3 Notification
In the event of a security incident that materially affects user data or platform availability, we will notify affected users through available contact channels in a timely manner. Notifications will include a description of the incident, the data or systems involved, and the steps taken or recommended.
8. Physical Security
Physical access to systems and infrastructure that process or store platform data is restricted to authorized personnel. Data center facilities used by our infrastructure providers maintain documented physical security controls including access logging, surveillance, and environmental protections.
9. Employee and Contractor Responsibilities
All individuals with access to HuskDrevos systems are required to adhere to security policies and complete relevant security awareness training. Personnel are expected to report suspected vulnerabilities, policy violations, or security incidents promptly through internal reporting channels. Failure to comply with security obligations may result in access revocation and further action.
10. User Responsibilities
Users of the HuskDrevos platform share responsibility for the security of their accounts. Users are expected to:
| Responsibility | Expectation |
|---|---|
| Password hygiene | Use a strong, unique password and do not share account credentials. |
| Account monitoring | Review account activity and report unauthorized access promptly. |
| Device security | Access the platform from devices that are reasonably secured and up to date. |
| Phishing awareness | Exercise caution with unsolicited communications claiming to be from HuskDrevos. |
| Reporting | Notify us of any suspected security issues related to your account or the platform. |
11. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities from security researchers and members of the public. If you believe you have identified a security issue affecting our platform, please contact us at info@huskdrevos.com with a clear description of the issue, steps to reproduce, and any supporting information. We commit to acknowledging reports promptly and working toward resolution in good faith. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.
12. Business Continuity and Backups
Critical platform data is backed up on a regular schedule. Backups are stored securely, encrypted, and tested periodically to verify recoverability. We maintain documented continuity procedures to restore service in the event of significant disruption.
13. Policy Review and Updates
This Security Policy is reviewed at least annually and updated as needed to reflect changes in our systems, practices, or the threat landscape. Significant updates will be communicated to users through the platform or via email. Continued use of the platform following such updates constitutes acceptance of the revised policy.
14. Contact
For questions, concerns, or reports related to this Security Policy, please contact us through any of the following channels:
| Channel | Details |
|---|---|
| info@huskdrevos.com | |
| Phone | +380 50 686 64 64 |
| Postal address | Klochkivska St, 99, Kharkiv, Kharkiv Oblast, Ukraine, 61058 |
| Web | huskdrevos.com/contact-us |