Security Policy
Last Updated: 13 December 2024
Jelami is committed to protecting the security of information handled through faryomir.com. This Security Policy describes the measures we take to safeguard our platform, your data, and the integrity of our services. By using our website, you acknowledge and accept the practices described here.
1. Scope
This policy applies to all systems, infrastructure, and services operated by Jelami, including our website, any associated web applications, and communications channels used to deliver our educational content and support services.
2. Data Protection Principles
We apply the following core principles when handling information:
- Minimal collection: We collect only the information necessary to provide and improve our services.
- Purpose limitation: Data is used solely for the purposes for which it was collected.
- Integrity: We take reasonable steps to ensure data remains accurate and is not improperly altered.
- Confidentiality: Access to personal and operational data is restricted to authorised personnel only.
3. Technical Security Measures
3.1 Encryption
All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS). We enforce HTTPS across all pages and services. Sensitive stored data is encrypted at rest using industry-standard encryption methods.
3.2 Access Controls
Access to internal systems and administrative interfaces is protected by strong authentication requirements. We apply the principle of least privilege, ensuring personnel can only access data and systems necessary for their role. Administrative access is reviewed periodically and revoked promptly when no longer required.
3.3 Infrastructure Security
Our infrastructure is hosted with reputable providers that maintain recognised security certifications. We apply regular security patches and updates to all operating systems, software dependencies, and third-party components. Firewalls and network segmentation are used to limit exposure of internal services.
3.4 Monitoring and Logging
We maintain logs of system activity and access events. These logs are monitored for anomalies, suspicious behaviour, and potential security incidents. Log data is retained for a defined period and protected against unauthorised modification.
4. Application Security
4.1 Secure Development Practices
Security is considered throughout our development process. We follow established secure coding guidelines and conduct code reviews that include security considerations. Dependencies are regularly audited for known vulnerabilities.
4.2 Input Validation
All user-supplied input is validated and sanitised before processing. We implement protections against common web application vulnerabilities including, but not limited to, cross-site scripting (XSS), SQL injection, and cross-site request forgery (CSRF).
4.3 Session Management
User sessions are managed securely. Session tokens are generated with sufficient entropy, transmitted only over encrypted connections, and invalidated upon logout or after a defined period of inactivity.
5. Third-Party Services
We may engage third-party service providers to support the operation of our platform. Where third parties process data on our behalf, we assess their security practices and require them to maintain appropriate safeguards. We are not responsible for the independent security practices of third-party websites linked from our content.
6. Incident Response
We maintain an internal process for identifying, responding to, and recovering from security incidents. In the event of a confirmed security breach that affects your data, we will take prompt action to contain the incident and notify affected users in a timely manner, consistent with our obligations and the nature of the incident.
If you believe you have identified a security vulnerability or incident involving our services, please contact us immediately at jelami@hotmail.com.
7. Vulnerability Disclosure
We welcome responsible disclosure of potential security vulnerabilities. If you discover a security issue affecting jelami.com, please report it to us privately before making any public disclosure. We ask that you:
- Provide sufficient detail for us to reproduce and assess the issue.
- Avoid accessing, modifying, or deleting data that does not belong to you.
- Allow us a reasonable period to investigate and remediate before any public disclosure.
Reports should be sent to jelami@hotmail.com. We will acknowledge receipt and keep you informed of our progress where appropriate.
8. Password and Account Security
Where account access is provided, we strongly encourage users to:
- Use a strong, unique password not shared with other services.
- Avoid sharing account credentials with others.
- Contact us promptly if you suspect unauthorised access to your account.
We will never ask for your password via email or any messaging channel.
9. Cookies and Tracking Technologies
We use cookies and similar technologies to support the operation and security of our platform. Certain cookies are essential for authentication and session management. Our use of cookies is described further in our Privacy Policy.
10. Data Retention and Deletion
We retain data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable obligations. When data is no longer needed, it is securely deleted or anonymised in a manner that prevents recovery.
11. Physical Security
Our services are hosted in facilities that maintain physical access controls, environmental protections, and redundancy measures. Physical access to servers and network equipment is restricted to authorised personnel of our infrastructure providers.
12. Business Continuity
We maintain backup procedures to support recovery of data and services in the event of a failure or incident. Backups are stored securely and tested periodically to verify their integrity and recoverability.
13. Employee Responsibilities
All personnel with access to our systems are required to adhere to internal security guidelines. This includes maintaining the confidentiality of access credentials, reporting suspected incidents promptly, and completing security awareness training appropriate to their role.
14. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or obligations. The date at the top of this page indicates when the policy was last revised. Continued use of our services following any update constitutes acceptance of the revised policy.
15. Contact
If you have questions about this Security Policy or our security practices, please contact us:
- Email: jelami@hotmail.com
-
Phone:
+61 409 554 563