CFOLogic is committed to ensuring the confidentiality, integrity, and availability of all data under its control. This page outlines the practices and measures we take to protect the sensitive information entrusted to us and to maintain compliance with applicable regulatory frameworks.
No physical servers; all data within the Microsoft ecosystem
Sensitive data encrypted in transit and at rest
On all accounts accessing our systems
Role-based access, revoked immediately when not needed
This policy applies to all personnel, contractors, and partners with access to CFOLogic's data systems and information. It governs all types of data - including financial records, personal information, and business records - processed or stored by CFOLogic, both electronically and physically.
We value client confidentiality and data protection above all, and are dedicated to maintaining the highest standards of information security and data privacy. Our policies are built to align with industry standards and regulatory requirements.
The three principles every control we run is designed to uphold.
Prevent unauthorised disclosure of information.
Prevent unauthorised changes to data.
Ensure data is available when it is needed.
All sensitive data, in transit and at rest, is encrypted using industry-standard encryption protocols.
Only authorised personnel may access sensitive client information, on a need-to-know basis, under a role-based access control (RBAC) system.
Real-time monitoring tools track all data access and ensure compliance with our access controls.
We regularly assess risks to our information systems and implement controls to mitigate them, protecting both data and systems.
Multiple layers of controls - firewall protection, encryption, intrusion detection, and secure user authentication.
Personal data is processed in line with applicable privacy regulations and handled with the utmost care. All staff and partners are trained on privacy and security.
All employees undergo regular training on information security and data privacy best practices - including recognising phishing attacks, handling data securely, and reporting security incidents.
Detection: staff are trained to identify and immediately report potential incidents. Investigation & mitigation: a structured response plan investigates the breach and mitigates risk. Notification: if a breach affects sensitive data, clients are notified in line with legal requirements and best practices.
Request the full Information Security & Data Privacy Policy, or talk to us about your security review. We'll come back to you within one business day.