Fundora Technologies Ltd

Information Security Policy

Effective Date: 29th June 2026Version: 1.0

1. Introduction

Fundora Technologies Ltd recognizes information security as a critical component of its operations. This Information Security Policy establishes the framework for protecting Fundora's systems, applications, customer information, business data and technology infrastructure.

2. Objectives

The objectives of this Policy are to ensure:

  1. confidentiality of information;
  2. integrity of systems and data;
  3. availability of services;
  4. prevention of unauthorized access;
  5. effective response to security incidents.

3. Information Security Governance

Fundora shall maintain an information security governance structure consisting of:

Board of Directors

Responsible for:

  • oversight;
  • approval of security strategy;
  • risk supervision.

Management

Responsible for:

  • implementation;
  • resource allocation;
  • enforcement.

Technology/Security Team

Responsible for:

  • system protection;
  • monitoring;
  • incident response.

4. Information Classification

Fundora classifies information as:

Confidential

Examples:

  • customer identity data;
  • financial information;
  • authentication data.

Internal

Examples:

  • internal procedures;
  • operational documents.

Public

Examples:

  • published information.

5. Access Control Policy

Fundora shall enforce:

  1. unique user accounts;
  2. strong authentication;
  3. least-privilege access;
  4. role-based permissions;
  5. periodic access reviews.

6. Authentication and Account Security

Security controls include:

  1. two-factor authentication;
  2. biometric verification;
  3. secure password requirements;
  4. session controls;
  5. login monitoring.

7. Encryption Policy

Fundora shall encrypt sensitive information:

  • during transmission;
  • during storage;
  • during processing where appropriate.

Encryption controls include secure encryption technologies including Tremble Vault.

8. System Security

Fundora shall maintain:

  1. secure software development practices;
  2. vulnerability management;
  3. system monitoring;
  4. security testing;
  5. patch management.

9. Application Security

Fundora applications shall be developed and maintained with:

  • secure coding practices;
  • access controls;
  • authentication requirements;
  • security testing.

10. Network Security

Fundora shall implement:

  1. network monitoring;
  2. firewall controls;
  3. intrusion detection measures;
  4. secure communications protocols.

11. Third-Party Security

Third parties shall be assessed before access to Fundora systems.

Requirements may include:

  • security reviews;
  • confidentiality agreements;
  • compliance obligations;
  • access restrictions.

12. Incident Response

Fundora shall maintain an incident response process.

Security incidents shall be:

  1. detected;
  2. contained;
  3. investigated;
  4. resolved;
  5. documented.

13. Business Continuity and Disaster Recovery

Fundora shall maintain measures including:

  • backups;
  • recovery procedures;
  • continuity planning;
  • system restoration processes.

14. Employee Security Awareness

Employees shall receive training on:

  • cybersecurity awareness;
  • phishing prevention;
  • password protection;
  • data handling.

15. Monitoring and Audit

Fundora may conduct:

  • security assessments;
  • system audits;
  • access reviews;
  • vulnerability assessments.

16. Policy Breaches

Violation of this Policy may result in:

  • access restrictions;
  • disciplinary action;
  • termination;
  • regulatory reporting.

17. Review

This Policy shall be reviewed periodically to ensure effectiveness.

Approved by

Board of Directors

Fundora Technologies Ltd