Legal

Information Security Policy

Effective October 8, 2026

The controls we apply to protect customer and business information.

Access control

  • Internal systems require an authenticated account; there is no shared login.
  • Administrative functions such as catalogue and lead management are restricted to named staff and administrator roles.
  • Access is removed when a person leaves or changes role.

Technical measures

  • All traffic to this website is served over encrypted HTTPS connections.
  • Customer records are held in a managed database with row-level access rules that deny access by default.
  • Uploaded media is stored in a private bucket with write access limited to authorised staff.
  • Credentials and API keys are held in a secret store and never committed to source code.

Organisational measures

  • Staff are instructed not to move customer data into personal accounts or devices.
  • Changes to the website and backend are reviewed before release.
  • Suspected security issues follow our Incident Response Policy.

Reporting a vulnerability

If you believe you have found a security weakness, email Gideon@aduanaglobaltrade.com with the details. Please do not publicly disclose it before we have had a chance to respond.

All policies