Contact Us

Eccentex Security Policy

Security built in to
everything we do

At Eccentex, protecting your data and safe operation is fundamental. Our security policy outlines the safeguards, standards, and practices we apply to maintain confidentiality, integrity, and availability across all solution components.

ECCENTEX SECURITY POLICY

Last reviewed:  August 19, 2026

Policy statement

Eccentex will protect the confidentiality, integrity, availability, and appropriate use of information through risk-based governance, secure-by-design technology practices, trained personnel, resilient operations, and measurable continual improvement.

Purpose of this policy

This policy establishes the principles, responsibilities, and minimum requirements for Eccentex’s information security program. It provides a consistent basis for managing security risk, meeting contractual and legal obligations, protecting customer trust, and supporting reliable business operations.

Policy Scope

This policy applies to all employees, officers, temporary personnel, interns, contractors, consultants, and other users who access Eccentex information or technology resources. It covers information in any form; corporate and customer-facing applications; cloud services; networks; endpoints; development and test environments; facilities; and third parties that process, store, transmit, or support Eccentex information.

  • Where local law, regulation, or contract imposes a stronger requirement, the stronger requirement applies.
  • Business units may adopt supporting standards and procedures that are more stringent, but not less stringent, than this policy.

Security objectives and principles

  • Risk-based: security decisions reflect business context, threat exposure, information sensitivity, customer commitments, and risk appetite.
  • Least privilege and need-to-know: access is limited to the minimum required and removed promptly when no longer needed.
  • Secure by design and by default: security and privacy are built into architecture, product development, configuration, and change management.
  • Defense in depth: preventive, detective, responsive, and recovery controls are layered to reduce single points of failure.
  • Accountability: control owners maintain evidence, address deficiencies, and report material risk through governance channels.
  • Continual improvement: controls are tested and improved using incidents, audits, metrics, threat intelligence, and business change.

Governance, risk, and compliance

Governance

Executive Management is accountable for oversight of information security. The CISO or designated security leader operates the security program, maintains the policy framework, reports material risks, and coordinates assurance activities. Business and system owners are accountable for risks and controls within their areas.

Risk management

  • Security risks shall be identified, assessed, recorded, assigned to accountable owners, and treated within approved risk tolerance.
  • Risk assessments shall occur at planned intervals and before material changes, including new products, acquisitions, architecture changes, sensitive data processing, and critical supplier engagements.
  • Risk treatment may include mitigation, avoidance, transfer, or formally approved acceptance. High or critical residual risk requires executive review.

Compliance and assurance

Eccentex shall identify applicable legal, regulatory, contractual, customer, and internal requirements. Control effectiveness shall be evaluated through monitoring, vulnerability management, testing, audits, assessments, and management review. Deficiencies shall have owners, target dates, and tracked remediation.

Roles and responsibilities

Role Core responsibilities
Executive Management Approve policy and risk appetite; provide resources; review material security risks and incidents.
CISO / Security leader Maintain the security program; advise the business; monitor risk; coordinate incident response, assurance, and reporting.
Business and information owners Classify information; approve access; assess risk; define retention and protection needs; accept residual risk within authority.
System and service owners Implement secure configuration, access, logging, resilience, patching, backup, and lifecycle controls.
People managers Authorize job-related access; ensure training; notify relevant teams of workforce changes.
Workforce members Follow policies; protect credentials and devices; complete training; report suspected events promptly.
Third parties Meet contractual security requirements, use access only as authorized, and report incidents affecting Eccentex promptly.

Information and asset management

Inventory and ownership

Information assets, systems, services, software, endpoints, repositories, and material third-party dependencies shall have identifiable owners and be recorded in appropriate inventories. Owners shall manage assets throughout acquisition, operation, transfer, and disposal.

Classification and handling

Information shall be classified according to sensitivity, business impact, contractual obligations, and applicable law. At minimum, Eccentex shall maintain handling rules for Public, Internal, Confidential, and Restricted information, or equivalent approved categories.

  • Access, sharing, storage, transmission, printing, retention, and disposal shall follow the assigned classification.
  • Sensitive information shall not be placed in unapproved services, personal accounts, or unmanaged devices.
  • Production data shall not be used in development or testing unless specifically authorized and protected; masked or synthetic data is preferred.

Retention and disposal

Information shall be retained only as long as required by business, legal, regulatory, contractual, and records-management obligations. Disposal shall be secure, verifiable where appropriate, and suitable for the media and information classification. Legal holds override routine deletion.

Identity and access management

  • Each user shall have a unique identity. Shared or generic accounts are prohibited unless justified, approved, controlled, and attributable.
  • Access shall be approved by an authorized owner, based on role and need-to-know, and provisioned through controlled processes.
  • Multi-factor authentication shall be used for privileged access, remote access, administrative interfaces, and other risk-designated systems.
  • Privileged access shall be segregated from ordinary user activity, tightly limited, logged, and reviewed at least quarterly.
  • Access rights shall be reviewed periodically and promptly adjusted upon transfer, role change, leave, or termination.
  • Passwords, tokens, keys, certificates, and other authenticators shall be protected, rotated or revoked when risk requires, and never shared or embedded insecurely.

Cryptography and secrets management

Approved cryptographic methods shall protect sensitive information in transit and at rest where warranted by classification, risk, contract, or law. Cryptographic keys and secrets shall be generated, stored, accessed, rotated, backed up where required, and retired through controlled lifecycle processes. Proprietary or obsolete cryptography shall not be used without documented approval.

Secure technology operations

Configuration, change, and vulnerability management

  • Systems and cloud services shall use approved secure baselines, hardened configurations, and controlled administrative interfaces.
  • Changes shall be authorized, tested proportionate to risk, documented, and capable of rollback. Emergency changes shall receive retrospective review.
  • Security patches and vulnerabilities shall be prioritized by exploitability, exposure, asset criticality, and business impact, with remediation targets defined in supporting standards.
  • Unsupported technology shall be retired, isolated, or covered by a time-bound, approved exception with compensating controls.

Endpoint, network, and cloud security

  • Corporate endpoints shall be managed, encrypted where appropriate, protected against malicious code, configured to lock automatically, and monitored in accordance with risk.
  • Networks and cloud environments shall use segmentation, controlled ingress and egress, secure remote access, configuration monitoring, and protection of management planes.
  • Only authorized hardware, software, and cloud services may connect to or process Eccentex information.

Logging and monitoring

Security-relevant activity shall be logged and monitored based on risk. Logs shall be time-synchronized, access-controlled, protected from unauthorized alteration, retained for defined periods, and available for investigation. Alerting and escalation shall cover material indicators of compromise, misuse, control failure, and service degradation.

Secure product and software development

Eccentex shall operate a secure development lifecycle for software, integrations, infrastructure-as-code, and material configuration changes.

  • Security and privacy requirements shall be defined during planning and design; material changes shall undergo threat modeling or equivalent risk review.
  • Code shall be version-controlled and subject to peer review, automated checks, dependency controls, secrets detection, and security testing proportionate to risk.
  • Development, test, and production environments shall be appropriately segregated. Production changes shall be traceable and restricted to authorized personnel and pipelines.
  • Third-party and open-source components shall be inventoried, assessed, maintained, and remediated when vulnerable or unsupported.
  • Security defects shall be prioritized and resolved according to severity and exposure. Release decisions shall not silently accept material unresolved risk.

Data protection and privacy

Personal data and customer information shall be processed lawfully, fairly, transparently, and only for authorized purposes. Eccentex shall apply data minimization, purpose limitation, access control, encryption, retention, deletion, and privacy-by-design practices appropriate to the data and processing context. Suspected unauthorized disclosure or privacy breach shall be reported through the incident process immediately.

Third-party and supply-chain security

  • Security due diligence shall be completed before engaging suppliers that access sensitive information, systems, source code, production environments, or critical services.
  • Contracts shall define applicable security, confidentiality, privacy, incident notification, audit/assurance, subcontractor, continuity, and return/deletion requirements.
  • Supplier access shall be time-bound where practicable, least-privileged, monitored, and removed when no longer required.
  • Critical suppliers shall be reviewed periodically based on risk, performance, changes, assurance evidence, and concentration or resilience concerns.

Physical and environmental security

Facilities and physical assets shall be protected against unauthorized access, damage, interference, and environmental hazards. Access to controlled areas shall be authorized and reviewed. Visitors shall be managed appropriately. Equipment and media shall be protected during use, transport, storage, maintenance, and disposal. Remote workers shall prevent unauthorized viewing, discussion, or access.

Human resources security and acceptable use

  • Screening shall be performed where lawful and appropriate to role risk. Security responsibilities shall be communicated before access is granted.
  • All workforce members shall complete security and privacy training at onboarding and at least annually, with role-based training for elevated responsibilities.
  • Eccentex resources shall be used primarily for authorized business purposes. Users shall not bypass controls, introduce malicious or unlicensed software, conduct unauthorized testing, or process Eccentex data in unapproved tools.
  • Users shall remain alert to phishing, social engineering, fraud, and accidental disclosure, and shall report suspected events promptly without attempting unauthorized investigation.
  • Security obligations, access return, and asset return shall be addressed at role change and separation.

Security incident management

Eccentex shall maintain and exercise an incident response capability. Anyone who suspects loss, unauthorized access, malware, credential compromise, data exposure, control bypass, or other security event shall report it immediately through approved channels.

  • Events shall be triaged, classified, contained, investigated, eradicated, and recovered according to documented procedures and assigned authority.
  • Evidence shall be preserved with appropriate chain of custody. Communications and notifications shall be coordinated with Legal, Privacy, Communications, customers, insurers, regulators, and law enforcement as applicable.
  • Material incidents shall receive post-incident review, root-cause analysis, corrective actions, and lessons learned.

Business continuity, backup, and recovery

Critical services and supporting assets shall have business continuity and disaster recovery arrangements based on business impact and risk. Recovery objectives, dependencies, roles, alternate arrangements, and communication paths shall be documented and tested periodically. Backups shall be protected, monitored, and restoration-tested; high-risk backups shall be isolated or otherwise protected against destructive compromise.

Security testing and assurance

  • Eccentex shall perform risk-based security testing, which may include vulnerability scanning, penetration testing, code analysis, configuration review, tabletop exercises, access reviews, and control audits.
  • Testing shall be authorized, scoped, conducted safely, and documented. Findings shall be risk-rated, assigned, tracked, and verified after remediation.
  • Independent assurance shall be obtained where required by risk, customer commitment, law, or governance expectations.

Policy exceptions

Exceptions require a documented business justification, risk assessment, compensating controls, accountable owner, defined scope, approval at the appropriate authority level, and an expiration date. Exceptions shall be recorded and reviewed before renewal. An exception does not waive legal, regulatory, or contractual duties.

  1. Submit the exception request before noncompliance occurs, except during a documented emergency.
  2. Assess residual risk and identify compensating controls and remediation milestones.
  3. Obtain approval from the information or system owner and Security; material residual risk requires executive acceptance.
  4. Track the exception to expiry, remediation, or formal renewal.

Violations and enforcement

Suspected violations shall be investigated fairly and consistently. Eccentex may restrict access, require remediation, take disciplinary action up to and including termination of employment or contract, pursue legal remedies, or notify authorities where appropriate. Good-faith reporting is protected from retaliation, subject to applicable law and company policy.

Measurement, review, and maintenance

Security leadership shall report meaningful indicators of risk, incidents, vulnerabilities, access governance, training, supplier assurance, resilience, and remediation to appropriate governance bodies. This policy shall be reviewed at least annually and after material legal, business, technology, threat, or incident changes. Approved changes shall be communicated to affected parties.

Eccentex Cloud Security Policy

Eccentex Cloud Security Policy is incorporated into Customer’s Eccentex Cloud Service Terms and Conditions agreement to describe the contractual requirements for information security provided by Eccentex to Customer related to the provision of Eccentex Cloud Services Customer has licensed from Eccentex pursuant to an agreement executed by both parties governing such provision and use of Eccentex Cloud Services (the “Agreement”).  These terms are applicable to the extent that Eccentex has access to and control over Customer Data.

Security Program

  • Security Standards. Eccentex has implemented and will maintain an information security program that follows generally accepted system security principles embodied in the ISO 27001 standard designed to protect Customer Data, as appropriate to the nature and scope of the Eccentex Cloud Services provided.
  • Security Awareness and Training. Eccentex has developed and will maintain an information security and awareness program delivered to all employees and appropriate contractors at the time of hire or contract commencement and annually thereafter.  With regard to Customer Data access, this includes information security, privacy, HIPAA security & privacy, GDRP, and PCI training.
  • Policies and Procedures. Eccentex will maintain appropriate policies and procedures to support the information security  Policies and procedures will be reviewed annually and updated as necessary.
  • Change Management. Eccentex will use a change management process based on Industry Standards to ensure all changes to the Eccentex Cloud Services environment are appropriately reviewed, tested, and approved.
  • Data Storage and Backup. Eccentex will create backups of Customer Data.  Customer Data will be stored and maintained solely in Azure Cloud with AES-256 Server-Side Encryption (SSE).  Backup data will not be stored on portable media.  Customer Data backups will be protected from unauthorized access.
  • Anti-virus and Anti-malware. Industry Standard anti-virus and anti-malware protection solutions are used on systems commonly affected by malware to protect infrastructure supporting Eccentex Cloud Services against malicious software, such as trojan horses, viruses, and worms.  Eccentex deploys File Integrity Management (FIM) solutions on all production systems, as well as robust monitoring of system access and command use.
  • Vulnerability and Patch Management. Eccentex will maintain a vulnerability management program that ensures compliance with Industry  Eccentex will assess all critical vulnerabilities to the Eccentex Cloud Services environment for access/vector complexity, authentication, impact, and integrity.  If the resulting risk is deemed to be “Critical” to Customer Data by Eccentex, Eccentex will endeavor to patch or mitigate affected systems within three (3) working days.
  • Data Deletion and Destruction. Eccentex will, and will ensure that sub-processors will, follow Industry Standard processes to delete obsolete data and sanitize or destroy retired equipment that formerly held Customer Data.
  • Penetration Testing. On at least an annual basis, Eccentex will conduct a vulnerability assessment and penetration testing engagement with an independent qualified vendor.  Issues identified during the engagement will be appropriately addressed within a reasonable time-frame commensurate with the identified risk level of the issue.

Product Architecture Security

  • Logical Separation Controls. Eccentex will employ effective logical separation controls based on Industry Standards to ensure that Customer Data is logically separated from other customer data within the Azure Cloud storage.
  • Firewall Services. Eccentex uses Azure Security Groups to protect the Eccentex Cloud Services  Eccentex maintains granular ingress and egress rules, and changes must be approved through Eccentex change management procedures.
  • Intrusion Detection System. Eccentex has implemented intrusion detection across the Eccentex Cloud Services environment.
  • No Wireless Networks. Eccentex will not use wireless networks in its Cloud Services environments.
  • Data Connections between Customer and the Eccentex Cloud Services Environment. All connections to browsers, mobile apps, and other components are secured via Hypertext Transfer Protocol Secure (HTTPS), Secure Real-time Transport Protocol (SRTP), Secure File Transfer Protocol (SFTP) and Transport Layer Security (TLS v1.2 or higher) over public Internet.
  • Data Connections between Eccentex Cloud Services Environment and Third Parties. Transmission or exchange of Customer Data with Customer and any Eccentex Vendor will be conducted using secure methods (e.g. TLS 1.2, HTTPS, SFTP).
  • Encryption Protection. Eccentex uses Industry Standard methods to support encryption of content at rest, with AES meeting FIPS 197, TLS 2 and above and Azure Server Side Encryption.
  • Logging and Monitoring. Eccentex will log security events from the operating perspective for all infrastructure providing Eccentex Cloud Services to Customer. Eccentex will monitor and investigate events that may indicate a Security Incident or  Event records will be retained at least one year.  Certain audit data is accessible to customers via the User Interface (UI).

User Access Control

  • Access Control. Eccentex will implement appropriate access controls to ensure only authorized Users have access to Customer Data within the Eccentex Cloud Services environment.
  • Customer User Access. Customer is responsible for managing User access controls within the application.  Eccentex Cloud Services application password requirements are configurable by Customer for minimum length, minimum letters, minimum numerals, minimum special characters, password expiration, and minimum age.  Customer defines user names and roles in a granular access permissions model.  Customer is entirely responsible for any failure by itself, its agents, contractors or employees (including without limitation all its users) to maintain the security of all usernames, passwords and other account information under its control.  Except in the event of a security lapse arising from gross negligence or willful action or inaction by Eccentex, Customer is entirely responsible for all use of Eccentex Cloud Services through Customer’s usernames and passwords, whether or not authorized by Customer, and all charges resulting from such use.  Customer will immediately notify Eccentex if Customer becomes aware of any unauthorized use of Eccentex Cloud Services.
  • Eccentex User Access. Eccentex will create individual user accounts for each Eccentex employee or contractor that has a business need to access Customer’s systems within the Eccentex Cloud Services environment.  The following guidelines will be followed regarding Eccentex user account management:
    • User accounts are requested and authorized by Eccentex.
    • Strong password controls are systematically.
    • Connections are required to be made via secure VPN using multi-factor authentication and strong passwords that expire every ninety (90) days.
    • Session time-outs are systematically enforced.
    • User accounts are promptly disabled upon employee termination or role transfer that eliminates a valid business need for access.

Business Continuity and Disaster recovery

  • Disruption Protection. Eccentex Cloud Services will be deployed and configured in a high-availability design.  The Eccentex Cloud Services environment is physically separated from Eccentex’ corporate network environment so that a disruption event involving the corporate environment does not impact the availability of Eccentex Cloud Services.
  • Business Continuity. Eccentex will maintain a corporate business continuity plan designed to ensure ongoing monitoring and support services will continue in the event of a disruption event involving the corporate environment.
  • Disaster Recovery. The Eccentex Cloud Services Azure platform takes advantage of the distributed nature of the Azure infrastructure to enable full multi-site disaster recovery by operating in multiple availability zones, which are distinct locations that are engineered to be insulated from one another.

Security Incident Response

  • Security Incident Response Program. Eccentex will maintain a Security Incident response program based on Industry Standards, which is designed to identify and respond to suspected and actual Security Incidents involving Customer  The program will be reviewed, tested and, if necessary, updated on at least an annual basis.  “Security Incident” means a confirmed event resulting in the unauthorized use, deletion, modification, disclosure, or access to Customer Data.
  • Notification. In the event of a Security Incident or other security event requiring notification under applicable law, Eccentex will notify Customer within twenty-four (24) hours and cooperate reasonably so Customer can make any required notifications relating to such event, unless Eccentex is requested specifically by law enforcement or a court order to not do so.
  • Notification Details. Eccentex will provide the following details to Customer regarding any Security Incidents: (i) dates Security Incident was identified and confirmed; (ii) nature and impact of the Security Incident; (iii) actions Eccentex has already taken; (iv) corrective measures to be taken; and (v) evaluation of alternatives and next steps.
  • Ongoing Communications. Eccentex will continue providing appropriate status reports to Customer regarding the resolution of the Security Incident and continually work in good faith to correct the Security Incident and prevent future such Security Incidents.  Eccentex will cooperate, as reasonably requested by Customer, to further investigate and resolve the Security Incident.

Data Center Productions

  • Eccentex contracts with MS Azure for Platform as a Service (PaaS).  Security and compliance certifications and/or attestation reports for Azure must be obtained directly from MS Azure. Azure may require Customer to execute additional non-disclosure agreements.  Eccentex may facilitate certain documentation upon request to Eccentex.

Use of Eccentex Cloud Services

  • Use Restrictions. Customer will not, and will not permit or authorize others to, use Eccentex Cloud Services for any of the following: (i) to violate applicable law; (ii) to transmit malicious code; (iii) to interfere with, unreasonably burden, or disrupt the integrity or performance of the Cloud Services or third-party data contained therein; (iv) to attempt to gain unauthorized access to systems or networks; and (v) to provide Eccentex Cloud Services to non-User third parties, including, by resale, license, lend or lease.
  • Customer Testing Restrictions. Customer will not perform any type of Penetration Testing, Denial of Service attack, or Vulnerability Assessment on Eccentex Cloud Services of any of the production, test, or development environments.  Authorized Penetration Testing in a test environment is available for a fee and must be coordinated with the Eccentex Sales and Cloud Services Security teams.
  • Prohibited Use. Customer will use commercially reasonable efforts to prevent and/or block any prohibited use by Users.
  • Customer Safeguards. Customer will maintain a reasonable and appropriate administrative, physical, and technical level of security regarding its account ID, password, antivirus and firewall protections, and connectivity with Eccentex Cloud Services.
  • Security Features. If the Cloud Services are to be used to transmit or process Personal Data, Customer will ensure all Personal Data is captured and used via security features made available by Eccentex.

Industry-Specific Standards

  • Eccentex security and operational controls are based on Industry Standard practices.  Nevertheless, Customer is solely responsible for achieving and maintaining any industry-specific certifications required for Customer’s

Privacy

Customer Data

  • Ownership and License. As between Eccentex and Customer, Customer retains ownership of and all intellectual property rights in Customer Data and grants to Eccentex a non-exclusive, non-sub-licensable (except to parties working on behalf of Eccentex), non-transferable, royalty-free license to access, process, store, transmit, and otherwise make use of the Customer Data as necessary to provide Eccentex Cloud Services and to otherwise fulfill Eccentex’ obligations under the Agreement.
  • Processing Locations. Unless provided for specifically elsewhere in the Agreement, Customer agrees Customer Data may be transferred or stored outside the country where Customer and its customers are located in order to perform support and troubleshooting services under the Agreement.
  • Consents. Customer represents and warrants it has obtained all consents necessary for Eccentex to collect, access, process, store, transmit, and otherwise use Customer Data in accordance with the Agreement.
  • Quality. Customer acknowledges that Eccentex has no control over the content or quality of Customer Data submitted to Eccentex Cloud Services.  Customer shall comply with all applicable requirements of integrity, quality, legality and other similar aspects in respect of Customer Data.  Eccentex disclaims expressly any duty to review or determine the legality, accuracy or completeness of Customer Data.

Definitions

For the purposes of these Eccentex Cloud Security Terms, the following defined terms shall have the meaning set forth below.

  • Cloud Services: Eccentex’ proprietary cloud services made available to Customer in the Azure environment. If Eccentex provides cloud services in other environments, modified cloud service terms will apply to those environments accordingly.
  • Customer Data: Customer’s proprietary information and information about Customer’s customers (including Personal Data) submitted through the Eccentex Cloud Services by Customer or its Users.
  • Data Center: a data center where the Eccentex Cloud Services environment is housed.
  • Industry Standard(s): generally accepted cloud information security practices, and specifically SOC 2. Such standards may be updated from time to time by changes in applicable law and accepted industry practices.
  • Personal Data: any information relating to Customer’s customers that is protected by applicable privacy law.
  • User: An individual who (i) is authorized by Customer and has been supplied a user identification and password(s) by Customer to access the Eccentex Cloud Services on Customer’s behalf.

Contact Us

Questions, comments and requests regarding these policies should be addressed to our Legal Office through the following means:

Eccentex
Legal Department
6101 West Centinela Ave.
Suite #110
Culver City, CA 90230
USA

Email Address: legal@eccentex.com