Information security & data privacy

Secure by design. Confidential by default.

CFOLogic is committed to ensuring the confidentiality, integrity, and availability of all data under its control. This page outlines the practices and measures we take to protect the sensitive information entrusted to us and to maintain compliance with applicable regulatory frameworks.

Request the full policy

Cloud-first, Microsoft 365

No physical servers; all data within the Microsoft ecosystem

AES-256 encryption

Sensitive data encrypted in transit and at rest

MFA enforced

On all accounts accessing our systems

Quarterly access reviews

Role-based access, revoked immediately when not needed


Scope & commitment

What this policy covers

This policy applies to all personnel, contractors, and partners with access to CFOLogic's data systems and information. It governs all types of data - including financial records, personal information, and business records - processed or stored by CFOLogic, both electronically and physically.

We value client confidentiality and data protection above all, and are dedicated to maintaining the highest standards of information security and data privacy. Our policies are built to align with industry standards and regulatory requirements.


Fundamental principles

Confidentiality, integrity, availability.

The three principles every control we run is designed to uphold.

Confidentiality

Prevent unauthorised disclosure of information.

Integrity

Prevent unauthorised changes to data.

Availability

Ensure data is available when it is needed.


Info-sec measures implemented

How we protect information.

Encryption

All sensitive data, in transit and at rest, is encrypted using industry-standard encryption protocols.

Access control

Only authorised personnel may access sensitive client information, on a need-to-know basis, under a role-based access control (RBAC) system.

Continuous monitoring

Real-time monitoring tools track all data access and ensure compliance with our access controls.

Risk management

We regularly assess risks to our information systems and implement controls to mitigate them, protecting both data and systems.

Data protection

Multiple layers of controls - firewall protection, encryption, intrusion detection, and secure user authentication.

Privacy

Personal data is processed in line with applicable privacy regulations and handled with the utmost care. All staff and partners are trained on privacy and security.


Data security measures implemented

The safeguards in place.

Microsoft 365 integration

All data storage and management runs on Microsoft 365 - a secure environment adhering to SOC 1, SOC 2, and ISO/IEC 27001.

Multi-factor authentication

Data encryption (AES-256)

Backup & disaster recovery

Physical security

Periodic access reviews


People & response

Training and incident response.

Employee training & awareness

All employees undergo regular training on information security and data privacy best practices - including recognising phishing attacks, handling data securely, and reporting security incidents.

Incident response & reporting

Detection: staff are trained to identify and immediately report potential incidents. Investigation & mitigation: a structured response plan investigates the breach and mitigates risk. Notification: if a breach affects sensitive data, clients are notified in line with legal requirements and best practices.

Have a question about how we handle your data?

Request the full Information Security & Data Privacy Policy, or talk to us about your security review. We'll come back to you within one business day.

Request the full policy Book a Discovery Call