Security & Trust
Security Policy
How Alethium protects its public website and the information shared through it.
Alethium is committed to protecting the confidentiality, integrity, and availability of information shared via our public website (alethium.io). This Security Policy outlines the measures we take to ensure our public-facing digital infrastructure is secure and resilient against threats. As a B2B platform built on trust — especially in the regulated supplements industry — we recognize that data protection and secure interactions are foundational to our business.
Purpose
Scope
Security Principles
-
Data MinimizationWe only collect essential personal data (e.g. contact form submissions) and process it in accordance with GDPR.
-
Defense in DepthMultiple layers of security controls are used to protect against unauthorized access and malicious activity.
-
Proactive MonitoringWe monitor traffic and access logs to detect anomalies or potential threats.
-
Continuous ImprovementOur website is reviewed and updated regularly to patch vulnerabilities and enhance resilience.
Technical Safeguards
-
HTTPS EncryptionAll data transmitted between the website and users is encrypted using TLS.
-
Secure HostingThe website is hosted with a reputable cloud provider that meets ISO/IEC 27001 and GDPR compliance standards.
-
Firewall and DDoS ProtectionWeb traffic is filtered through a Web Application Firewall (WAF) and protected by automated denial-of-service mitigation tools.
-
Security HeadersHTTP headers such as Content-Security-Policy, X-Content-Type-Options, and Strict-Transport-Security are used to guard against common vulnerabilities.
Content & Form Security
-
Input ValidationAll user input from contact forms or newsletter subscriptions is sanitized to prevent injection attacks.
-
Spam ProtectionCAPTCHA and anti-bot measures are deployed to reduce spam submissions and abuse.
-
File Upload RestrictionsNo file uploads are permitted through the public website without explicit validation and virus scanning.
Access & Change Control
-
Role-Based AccessOnly authorized team members may access the website's backend or make content changes.
-
Version Control & Change LoggingAll code and content changes are version-controlled and logged.
-
Two-Factor Authentication (2FA)Administrative access to the website is protected by multi-factor authentication.
Third-Party Integrations
Incident Response
- 1 Investigate and contain the breach immediately.
- 2 Notify affected parties if applicable.
- 3 Report to supervisory authorities if legally required.
- 4 Document the incident and update security measures.
User Responsibilities
- Refrain from attempting unauthorized access to any part of the platform.
- Report any suspicious activity to security@alethium.io.
- Avoid submitting sensitive personal data via contact forms.
Policy Review
Contact
End of Security Policy
This policy applies to alethium.io and its associated public-facing services. For questions about how we handle personal data more broadly, please see our Privacy Policy.