Our Security Approach
Normiqo follows a risk-based security approach appropriate to the services we provide. Measures may vary by deployment, product edition, infrastructure arrangement and contractual requirements.
Secure Infrastructure and Communication
- Cloud infrastructure selected for availability, reliability and operational control
- Encrypted browser communication using HTTPS/TLS
- Environment and access controls designed to limit unauthorized system access
- Monitoring and logging appropriate to the deployed service
Identity and Access Management
- Role-based access controls within supported product workflows
- User authentication and controlled administrative access
- Access granted according to business responsibilities and least-access principles where practical
- Access review and removal processes for authorized personnel
Customer Data Protection
Customer information is processed only for legitimate service, support, implementation and contractual purposes. Access is restricted to authorized personnel and service providers who require it for their responsibilities.
Customers remain responsible for managing their users, roles, passwords, endpoint security, data quality and lawful use of the platform.
Backup, Recovery and Availability
Backup and recovery mechanisms are maintained according to the applicable hosting arrangement and service scope. Recovery objectives and responsibilities may be defined in customer-specific agreements. Customers should also maintain appropriate exports or independent records where required by their own continuity policies.
Monitoring and Continuous Improvement
We monitor platform performance and security indicators, investigate relevant events and improve controls as technology, threats and business requirements evolve. Updates, fixes and operational improvements are prioritized based on risk and service impact.
Service Providers
Normiqo may rely on cloud, communications, monitoring and other technology providers. We select providers based on business requirements and apply reasonable controls to their access and use of information.
Responsible Disclosure
If you believe you have discovered a security vulnerability affecting a Normiqo website or product, please report it responsibly. Include enough information for us to understand and reproduce the issue, and do not access, modify or disclose data that does not belong to you.
Security Questions
Customers may contact their Normiqo representative for security information relevant to a specific deployment or commercial engagement.
