Legal
Information Security Policy
Effective October 8, 2026
The controls we apply to protect customer and business information.
Access control
- Internal systems require an authenticated account; there is no shared login.
- Administrative functions such as catalogue and lead management are restricted to named staff and administrator roles.
- Access is removed when a person leaves or changes role.
Technical measures
- All traffic to this website is served over encrypted HTTPS connections.
- Customer records are held in a managed database with row-level access rules that deny access by default.
- Uploaded media is stored in a private bucket with write access limited to authorised staff.
- Credentials and API keys are held in a secret store and never committed to source code.
Organisational measures
- Staff are instructed not to move customer data into personal accounts or devices.
- Changes to the website and backend are reviewed before release.
- Suspected security issues follow our Incident Response Policy.
Reporting a vulnerability
If you believe you have found a security weakness, email Gideon@aduanaglobaltrade.com with the details. Please do not publicly disclose it before we have had a chance to respond.