Security Policy
Last Updated: January 2025
At Evolution Software Services, LLC ("Evolution Software," "we," "us," or "our"), security is a top priority. We are committed to protecting the confidentiality, integrity, and availability of our systems, services, and the data entrusted to us by our clients and users.
This Security Policy outlines our approach to information security, the measures we implement to safeguard data, and how we respond to security incidents.
Data Protection
Encryption: We use industry-standard encryption protocols (TLS 1.2+) to protect data in transit. Sensitive data at rest is encrypted using AES-256 or equivalent encryption standards.
Access Controls: We implement role-based access control (RBAC) to ensure that only authorized personnel have access to sensitive systems and data. Access is granted on a need-to-know basis.
Authentication: Multi-factor authentication (MFA) is required for all administrative access to production systems and sensitive data.
Infrastructure Security
Cloud Security: Our infrastructure is hosted on secure, SOC 2 Type II certified cloud platforms. We leverage cloud-native security features including firewalls, DDoS protection, and intrusion detection systems.
Network Security: We implement network segmentation, private subnets, and security groups to isolate sensitive systems and limit exposure.
Monitoring: Our systems are continuously monitored for suspicious activity, unauthorized access attempts, and potential security threats.
Application Security
Secure Development: We follow secure coding practices and conduct regular code reviews to identify and remediate security vulnerabilities.
Vulnerability Management: We perform regular security assessments, penetration testing, and vulnerability scans to identify and address potential weaknesses.
Dependency Management: We maintain up-to-date dependencies and promptly apply security patches to address known vulnerabilities.
Privacy & Compliance
Data Minimization: We collect and retain only the data necessary to provide our services and comply with legal obligations.
Privacy by Design: Security and privacy considerations are integrated into every stage of our development process.
Compliance: We adhere to applicable data protection regulations and industry standards, including GDPR, CCPA, and SOC 2 requirements where applicable.
Incident Response
Incident Management: We maintain a documented incident response plan to quickly identify, contain, and remediate security incidents.
Notification: In the event of a data breach that affects personal information, we will notify affected parties and relevant authorities in accordance with applicable laws and regulations.
Post-Incident Review: Following any security incident, we conduct a thorough review to identify root causes and implement measures to prevent recurrence.
Reporting Security Vulnerabilities
If you discover a security vulnerability in our systems or services, we encourage you to report it to us responsibly. Please do not publicly disclose the issue until we have had an opportunity to address it.
To report a security issue, please email us at: security@evolutionsoftwareservicesllc.com
Please include as much detail as possible, including steps to reproduce the issue, potential impact, and any relevant screenshots or logs.
Employee Security Training
All Evolution Software employees and contractors receive security awareness training and are required to follow our security policies and procedures. We conduct regular training updates to ensure our team stays informed about emerging threats and best practices.
Third-Party Vendors
We carefully vet third-party vendors and service providers to ensure they meet our security standards. We require vendors to maintain appropriate security controls and comply with applicable data protection requirements.
Policy Updates
We regularly review and update this Security Policy to reflect changes in our practices, technology, and regulatory requirements. The "Last Updated" date at the top of this page indicates when the policy was last revised.
Questions About Security?
If you have questions about our security practices or this Security Policy, please contact us:
Email: security@evolutionsoftwareservicesllc.com
Phone: (850) 655-1319
Address: 1056 Morning Stroll Ln, Jacksonville, FL 32221