Last Updated: November 15, 2025
Contact: hello@mynestup.com

1. Introduction

MyNestup is committed to protecting the confidentiality, integrity, and availability of all data processed through our platform. This Digital Security Policy outlines the technical, administrative, and operational safeguards we employ to defend against unauthorized access, data breaches, and security threats.

This policy applies to:

  • All MyNestup systems and infrastructure
  • Employees, contractors, contributors, and partners
  • Data processed across our website, services, and digital operations

2. Security Governance

MyNestup maintains a structured security framework that includes:

  • Ongoing risk assessments
  • Security awareness training
  • Incident response planning
  • Access control governance
  • Documentation of security protocols

A designated security lead oversees implementation and compliance.

3. Access Control & Authentication

3.1 User Access Controls

We enforce the following controls for internal systems:

  • Role-based access (RBAC)
  • Least privilege principle
  • Password complexity requirements
  • Regular access reviews

3.2 Authentication Measures

We use industry-standard security measures including:

  • HTTPS/TLS encryption
  • Strong password policies
  • Multi-factor authentication (MFA) where applicable
  • Session timeout and automatic logouts

4. Data Protection Measures

4.1 Encryption

  • Data in transit: protected by TLS 1.2+ encryption
  • Data at rest: encrypted where appropriate depending on sensitivity

4.2 Data Minimization

We only collect and store the necessary data required to operate our services.

4.3 Secure Data Storage

Data is stored on secure servers operated by reputable service providers with global compliance certifications.

5. Network & Infrastructure Security

We implement defense-in-depth strategies including:

  • Firewalls and intrusion detection/prevention systems (IDS/IPS)
  • Regular vulnerability scanning
  • Server hardening and patch management
  • Distributed denial-of-service (DDoS) mitigation measures

6. Application Security

Our development practices include:

  • Secure coding standards
  • Vulnerability testing (automated and manual)
  • Regular patching and update procedures
  • Use of trusted third-party libraries and frameworks

Critical issues are prioritized and remediated promptly.

7. Vendor & Third-Party Security

We evaluate third parties and subprocessors based on:

  • Compliance certifications (ISO 27001, SOC 2, etc.)
  • Data protection policies
  • Contractual security assurances
  • Ongoing risk assessments

Vendors lacking sufficient security posture are not engaged.

8. Monitoring, Logging & Auditing

We maintain logging and monitoring processes to:

  • Detect suspicious activity
  • Track authentication attempts
  • Monitor system performance
  • Analyze security events

Logs are reviewed routinely and stored securely.

9. Incident Response & Breach Management

In the event of a security incident, MyNestup follows a structured procedure:

  1. Identification and confirmation of incident
  2. Containment of affected systems
  3. Investigation and root-cause analysis
  4. Notification of affected users and authorities where required (GDPR Art. 33/34, CCPA timelines)
  5. Remediation and post-incident review

We aim for rapid response to minimize damage and restore normal operations.

10. Employee & Contributor Security Training

All individuals with access to internal systems receive:

  • Annual cybersecurity training
  • Anti-phishing awareness sessions
  • Data protection and privacy compliance training

Training is mandatory and recorded for audit compliance.

11. Data Backup & Recovery

We maintain regular backups of critical data to ensure:

  • Business continuity
  • Disaster recovery capability
  • Redundant storage across secure data centers

Backups are encrypted and tested periodically.

12. Device & Endpoint Security

To protect endpoints, we enforce:

  • Mandatory antivirus/antimalware software
  • Disk encryption for employee devices
  • Restrictions on external storage devices
  • Secure Wi-Fi and VPN requirements for remote access

13. Continuous Improvement

MyNestup continuously evaluates and improves its security posture through:

  • Regular audits
  • Penetration testing
  • Updated security tools
  • Policy revisions aligned with evolving threats and regulations

14. User Responsibilities

Users are encouraged to protect their own security by:

  • Using strong, unique passwords
  • Enabling MFA where applicable
  • Keeping software and devices updated
  • Reporting suspicious activity immediately

15. Changes to This Policy

We may update this Digital Security Policy as needed to comply with new regulations, industry best practices, or operational enhancements. Any updates will be reflected in the “Last Updated” date November 15, 2025.