
Security Statement
Our commitment to protecting the information entrusted to us by clients, partners, and users.
At INFOWATCH LLC, security is at the core of everything we do. As a cybersecurity consulting firm specializing in Governance, Risk Management, Compliance (GRC), Information Assurance, and Cybersecurity Advisory Services, we understand the importance of protecting information assets, maintaining confidentiality, and preserving trust. We are committed to implementing and maintaining reasonable administrative, technical, and organizational security measures designed to safeguard information entrusted to us by our clients, partners, employees, and website users.
Security Principles
Confidentiality
Protect information from unauthorized access, disclosure, or misuse.
Integrity
Controls to maintain the accuracy, completeness, and reliability of information.
Availability
Systems, data, and services remain available and resilient.
Accountability
Governance processes promoting security oversight, risk management, and continuous improvement.
Security Controls
We apply a defense-in-depth approach across the following areas:
Access Management
- Role-based access controls
- Least-privilege principles
- Multi-factor authentication (MFA)
- Strong password requirements
- Periodic access reviews
Data Protection
- Encryption of sensitive data where appropriate
- Secure transmission protocols (HTTPS/TLS)
- Secure data storage practices
- Backup and recovery procedures
Network Security
- Firewalls and security monitoring
- Threat detection technologies
- Vulnerability management processes
- Secure remote access controls
Endpoint Security
- Endpoint protection solutions
- Security patch management
- Device security monitoring
- Malware prevention controls
Security Awareness
- Employee cybersecurity training
- Security awareness initiatives
- Phishing awareness programs
- Ongoing professional development
Security Monitoring
We maintain processes to monitor security events, detect suspicious activity, respond to identified threats, investigate potential incidents, and improve controls based on lessons learned. No environment can be guaranteed completely secure, but threats are continuously evaluated.
Incident Response
Our incident response process follows these steps:
- Identify potential security incidents
- Contain threats and limit impact
- Investigate root causes
- Implement corrective actions
- Communicate appropriately with affected parties when required
Client Information Protection
- Protecting confidential information
- Limiting access to authorized personnel
- Following contractual security requirements
- Supporting privacy and compliance obligations
- Maintaining professional and ethical standards
Responsible Disclosure
We encourage security researchers to report potential vulnerabilities to enquiries@theinfowatch.com, including a description, reproduction steps, potential impact, and contact information. We request good faith, no disruption, no data access, modification, or deletion, and reasonable time for remediation. See our full Responsible Disclosure Policy.
Security Shared Responsibility
Users play a role too:
- Protecting account credentials
- Using strong passwords
- Enabling MFA where available
- Reporting suspicious activity
- Maintaining secure devices and networks
Continuous Improvement
Our ongoing commitment is supported through:
- Risk assessments
- Security reviews
- Emerging threat analysis
- Staff training
- Technology enhancements
- Process improvements
Contact Us
- INFOWATCH LLC
- Security Inquiries: enquiries@theinfowatch.com
- Privacy Inquiries: enquiries@theinfowatch.com
- General Information: enquiries@theinfowatch.com
- Website: https://theinfowatch.com/
