Legal and governance
Public information security policy
Version 1.0 · Effective 04/08/2026
1. PURPOSE
This policy establishes public principles to protect the confidentiality, integrity and availability of information managed by Celestium Soft.
2. PRINCIPLES
Security and privacy by design; least privilege; separation of duties; risk-based management; traceability; continuous improvement; shared responsibility with providers and clients.
3. TECHNICAL CONTROLS
Secure authentication, robust password algorithms, protected sessions, role-based access, prepared queries, input validation, CSRF protection, security headers, TLS encryption, secret management, encrypted backups and event logging.
4. ORGANIZATIONAL CONTROLS
Asset and data inventories, risk assessment, change management, information classification, provider review, continuity, training, incident management and periodic access review.
5. VULNERABILITY REPORTING
Security findings may be reported responsibly to info@celestiumsoft.com. Destructive testing, access to third-party data, service disruption and extortion are prohibited.
6. INCIDENTS
Incidents are recorded, classified, contained, investigated and closed with lessons learned. Where personal data is affected, the applicable assessment and notification procedure is followed.
7. STANDARDS ALIGNMENT
The platform incorporates controls inspired by ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27017. This statement is not a certification; certification requires an organizational ISMS, defined scope and independent audit.
This policy establishes public principles to protect the confidentiality, integrity and availability of information managed by Celestium Soft.
2. PRINCIPLES
Security and privacy by design; least privilege; separation of duties; risk-based management; traceability; continuous improvement; shared responsibility with providers and clients.
3. TECHNICAL CONTROLS
Secure authentication, robust password algorithms, protected sessions, role-based access, prepared queries, input validation, CSRF protection, security headers, TLS encryption, secret management, encrypted backups and event logging.
4. ORGANIZATIONAL CONTROLS
Asset and data inventories, risk assessment, change management, information classification, provider review, continuity, training, incident management and periodic access review.
5. VULNERABILITY REPORTING
Security findings may be reported responsibly to info@celestiumsoft.com. Destructive testing, access to third-party data, service disruption and extortion are prohibited.
6. INCIDENTS
Incidents are recorded, classified, contained, investigated and closed with lessons learned. Where personal data is affected, the applicable assessment and notification procedure is followed.
7. STANDARDS ALIGNMENT
The platform incorporates controls inspired by ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27017. This statement is not a certification; certification requires an organizational ISMS, defined scope and independent audit.