strategynet.ai
Security

Cybersecurity Policy

The administrative, technical, and physical safeguards StrategyNet uses to protect its information, systems, and services.

Last updated: July 30, 2026

1. Purpose, scope, and governance

StrategyNet maintains a risk-based security program designed to protect the confidentiality, integrity, and availability of information and systems. This policy applies to personnel, software, devices, infrastructure, facilities, and service providers used to operate the StrategyNet websites, applications, APIs, research tools, and support services (collectively, the “Services”).

Security and Engineering owns this policy, coordinates its implementation, and reports material risks to management. The policy is reviewed at least annually and after a material change to the Services, threat environment, legal requirements, or a significant security incident. Supporting standards, procedures, and technical configurations are maintained separately and are not publicly disclosed.

2. Data classification and handling

Information is classified according to sensitivity and business impact:

  • Restricted: credentials, private keys, authentication tokens, third-party account authorizations, regulated payment data, and other information whose compromise could create a material security, legal, or customer impact.
  • Confidential: personal information, customer content and configurations, non-public business information, source code, and non-public operational or security records.
  • Internal: routine business and operational information not intended for public distribution.
  • Public: information approved for public release.

Restricted and Confidential information must be collected and retained only as reasonably necessary, accessed only for an authorized purpose, and shared only with approved recipients. Production data may not be copied to personal accounts or unmanaged systems. Retention is based on legal, contractual, security, and operational needs. When information is no longer required, it is securely deleted or rendered inaccessible in accordance with the capabilities of the applicable system and provider.

3. Access control and privileged access management

Access is granted under least-privilege and need-to-know principles using unique user identities and role-appropriate permissions. Privileged and production access is limited to authorized personnel, requires multi-factor authentication where the system supports it, and is separated from ordinary end-user access where practical.

  • Access is approved based on job responsibility and reviewed periodically and after material role changes.
  • Access is removed promptly when no longer required, including upon separation from the company.
  • Shared administrative credentials are prohibited where individual accounts are available.
  • Service credentials, tokens, and cryptographic keys must be scoped, stored outside client code and source control, rotated based on risk, and revoked when compromised or no longer required.
  • Material administrative and authentication events are logged where supported and reviewed when investigating security or operational concerns.

4. Encryption of data at rest and in transit

Production Services must use industry-standard encrypted protocols for data in transit. Plaintext transmission of Restricted or Confidential information over public networks is prohibited. Restricted and Confidential information stored in production systems and backups is protected by managed-platform or application-level encryption appropriate to the risk and the capabilities of the system.

Encryption keys and other secrets are logically separated from the information they protect, access is restricted, and rotation or revocation is performed when required. Secrets must not be placed in public repositories, client-distributed code, URLs, or application logs.

5. Endpoint and network protection

Corporate workstations must run supported operating systems with security updates, host-firewall protections, and built-in or approved anti-malware controls enabled. Automatic operating-system and malware-definition updates must be enabled where available. Devices used to access Restricted information must use automatic screen locking and protected user accounts. Storage of Restricted information on corporate workstations must be minimized and limited to an approved business need, with access controls appropriate to the information’s classification.

Production workloads use managed hosting or hardened systems with unnecessary services disabled and network exposure limited to required ports and protocols. Administrative access is restricted and authenticated. At company-controlled network boundaries, StrategyNet uses network security gateways for stateful firewalling and intrusion detection and prevention. Gateway firmware and threat signatures must be kept current, prevention mode must be used for covered networks, and significant detections must be reviewed. These network controls supplement rather than replace host-level endpoint protections.

6. Vulnerability management and patch management

StrategyNet monitors relevant provider notices, software advisories, dependencies, code changes, and security findings. New systems and material changes receive security review proportionate to risk. Suspected vulnerabilities are validated, prioritized by exploitability and business impact, tracked through resolution, and retested when appropriate.

Unless a documented exception or compensating control is approved, target remediation is:

  • Critical severity: as soon as practicable and normally within 7 calendar days;
  • High severity: normally within 30 calendar days;
  • Medium severity: normally within 90 calendar days; and
  • Low severity: based on risk and the normal maintenance cycle.

Supported operating systems, applications, network devices, and production dependencies are patched on a risk-based schedule. Emergency changes may be expedited when active exploitation or material exposure is identified.

7. Incident response and disaster recovery

Suspected security events are reported promptly and assessed for scope, severity, affected information, and legal or contractual obligations. Response activities include, as appropriate, detection and analysis, containment, evidence preservation, eradication, credential revocation, recovery, validation, communication, and a post-incident review. StrategyNet will notify affected customers, partners, authorities, or other parties when required by applicable law or contract.

Systems are designed for recovery in proportion to their business criticality. StrategyNet uses version-controlled software and provider or system backup and recovery capabilities, maintains procedures to rebuild or restore critical services, and tests recovery procedures periodically. Following a disruption, service integrity and security controls are validated before normal operations resume.

8. Physical security

StrategyNet primarily uses cloud-hosted production infrastructure and does not operate its own production data center. Physical and environmental safeguards for cloud facilities are evaluated through vendor risk management. Company-controlled computers, network equipment, and records are kept in access-controlled locations. Portable devices must be protected against unauthorized access and must not be left unattended in insecure locations while unlocked.

9. Vendor risk management

Service providers are evaluated before onboarding and periodically thereafter based on their criticality, data access, and the risk they present to the Services. Review may include security and privacy practices, independent assurance reports or certifications, resilience, incident-notification commitments, data location and deletion, subcontractors, and contractual safeguards.

Vendors receive only the information and access reasonably necessary to provide the approved service. Material vendor changes and incidents are evaluated, and access is removed and information returned or deleted when a relationship ends, subject to legal and technical retention requirements.

10. Security awareness, exceptions, and contact

Personnel are expected to follow secure development and information-handling practices, protect credentials, recognize suspicious activity, and report suspected incidents. Exceptions to this policy require documented risk review, approval by the policy owner, appropriate compensating controls, and an expiration or review date.

Security concerns may be reported through our contact page or to info@strategynet.ai. Do not include passwords, private keys, authentication codes, or other secrets in an initial report.