Last Updated: November 15, 2025
Contact: hello@mynestup.com
1. Introduction
MyNestup is committed to protecting the confidentiality, integrity, and availability of all data processed through our platform. This Digital Security Policy outlines the technical, administrative, and operational safeguards we employ to defend against unauthorized access, data breaches, and security threats.
This policy applies to:
- All MyNestup systems and infrastructure
- Employees, contractors, contributors, and partners
- Data processed across our website, services, and digital operations
2. Security Governance
MyNestup maintains a structured security framework that includes:
- Ongoing risk assessments
- Security awareness training
- Incident response planning
- Access control governance
- Documentation of security protocols
A designated security lead oversees implementation and compliance.
3. Access Control & Authentication
3.1 User Access Controls
We enforce the following controls for internal systems:
- Role-based access (RBAC)
- Least privilege principle
- Password complexity requirements
- Regular access reviews
3.2 Authentication Measures
We use industry-standard security measures including:
- HTTPS/TLS encryption
- Strong password policies
- Multi-factor authentication (MFA) where applicable
- Session timeout and automatic logouts
4. Data Protection Measures
4.1 Encryption
- Data in transit: protected by TLS 1.2+ encryption
- Data at rest: encrypted where appropriate depending on sensitivity
4.2 Data Minimization
We only collect and store the necessary data required to operate our services.
4.3 Secure Data Storage
Data is stored on secure servers operated by reputable service providers with global compliance certifications.
5. Network & Infrastructure Security
We implement defense-in-depth strategies including:
- Firewalls and intrusion detection/prevention systems (IDS/IPS)
- Regular vulnerability scanning
- Server hardening and patch management
- Distributed denial-of-service (DDoS) mitigation measures
6. Application Security
Our development practices include:
- Secure coding standards
- Vulnerability testing (automated and manual)
- Regular patching and update procedures
- Use of trusted third-party libraries and frameworks
Critical issues are prioritized and remediated promptly.
7. Vendor & Third-Party Security
We evaluate third parties and subprocessors based on:
- Compliance certifications (ISO 27001, SOC 2, etc.)
- Data protection policies
- Contractual security assurances
- Ongoing risk assessments
Vendors lacking sufficient security posture are not engaged.
8. Monitoring, Logging & Auditing
We maintain logging and monitoring processes to:
- Detect suspicious activity
- Track authentication attempts
- Monitor system performance
- Analyze security events
Logs are reviewed routinely and stored securely.
9. Incident Response & Breach Management
In the event of a security incident, MyNestup follows a structured procedure:
- Identification and confirmation of incident
- Containment of affected systems
- Investigation and root-cause analysis
- Notification of affected users and authorities where required (GDPR Art. 33/34, CCPA timelines)
- Remediation and post-incident review
We aim for rapid response to minimize damage and restore normal operations.
10. Employee & Contributor Security Training
All individuals with access to internal systems receive:
- Annual cybersecurity training
- Anti-phishing awareness sessions
- Data protection and privacy compliance training
Training is mandatory and recorded for audit compliance.
11. Data Backup & Recovery
We maintain regular backups of critical data to ensure:
- Business continuity
- Disaster recovery capability
- Redundant storage across secure data centers
Backups are encrypted and tested periodically.
12. Device & Endpoint Security
To protect endpoints, we enforce:
- Mandatory antivirus/antimalware software
- Disk encryption for employee devices
- Restrictions on external storage devices
- Secure Wi-Fi and VPN requirements for remote access
13. Continuous Improvement
MyNestup continuously evaluates and improves its security posture through:
- Regular audits
- Penetration testing
- Updated security tools
- Policy revisions aligned with evolving threats and regulations
14. User Responsibilities
Users are encouraged to protect their own security by:
- Using strong, unique passwords
- Enabling MFA where applicable
- Keeping software and devices updated
- Reporting suspicious activity immediately
15. Changes to This Policy
We may update this Digital Security Policy as needed to comply with new regulations, industry best practices, or operational enhancements. Any updates will be reflected in the “Last Updated” date November 15, 2025.