Security

Security is part of good technology.

We believe security should be considered from the beginning of a project and continuously maintained throughout the life of a system.

Our approach to security

Our Approach

Build securely.
Maintain responsibly.

Security isn't something that can simply be added at the end of a project.

It involves understanding the information a system handles, who needs access to it, how systems communicate, and what could happen when something goes wrong.

We aim to incorporate appropriate security considerations into the way we design, develop, deploy, and maintain digital solutions.

Security Areas

Practical security across the technology lifecycle.

Security requirements vary depending on the project, data, architecture, technology, and business environment. These are some of the areas we consider when designing and maintaining systems.

Access Control

Access to systems and information should be limited to authorized users and appropriate roles.

Secure Development

We consider security throughout the development process rather than treating it as an afterthought.

Data Protection

We consider how information is collected, stored, transmitted, accessed, and retained.

Monitoring & Awareness

We work to identify unusual activity, technical issues, and potential security concerns as early as reasonably possible.

Responsible Access

We aim to ensure that people have access only to the systems and information necessary for their responsibilities.

Continuous Improvement

Security is an ongoing process. We review and improve our practices as technology and threats evolve.

Secure Development

Security belongs in the development process.

The technologies and controls used will depend on the project, but security considerations can be incorporated throughout the development lifecycle.

Understanding application requirements and potential risks
Appropriate authentication and authorization controls
Role-based access where appropriate
Input validation and secure handling of application data
Secure API and system integration practices
Protection of sensitive configuration and credentials
Dependency and technology maintenance
Testing and review appropriate to the project

Security Principles

Simple principles. Consistent thinking.

01

Security by Design

Security considerations should be part of planning, architecture, development, deployment, and ongoing maintenance.

02

Least Privilege

Access should be limited to what is necessary for a person, system, or service to perform its intended function.

03

Protect Sensitive Information

Sensitive information should receive appropriate safeguards throughout its lifecycle.

04

Keep Systems Maintainable

Well-maintained systems are easier to monitor, update, patch, and secure over time.

Security Concerns

Found something that doesn't look right?

If you believe you've discovered a security vulnerability, suspicious activity, or another security issue involving an Awonsa website or system, please let us know.

Responsible disclosure helps us investigate potential issues and take appropriate action.

Responsible Disclosure

Please provide enough information for us to understand and reproduce the issue where possible.

Security Contact

security@awonsa.com

Please do not include passwords, authentication tokens, or unnecessary personal information in your initial report.

Security is a shared responsibility.

We work to build and maintain secure systems, but security also depends on how systems are configured, accessed, maintained, and used. We encourage our clients and users to follow good security practices and keep their credentials protected.

Building something that needs to be secure?

Let's talk about your requirements, your risks, and the right approach for your business.

Talk to Awonsa