Security Policy
The encryption, authentication, access controls, monitoring and incident response that protect your data.
1. Overview
Protecting your information is fundamental to how Nacravo operates. This Security Policy describes the technical and organisational measures we use to keep personal data and our systems secure. It complements our Privacy Policy.
2. Encryption — TLS 1.3 & AES-256
Our website is served exclusively over HTTPS using TLS 1.3 (with TLS 1.2 as a secure fallback), so data exchanged between your browser and our site is encrypted in transit. Sensitive data at rest, such as OAuth tokens, is protected with AES-256 encryption.
3. Secure Authentication & OAuth
Where we connect to third-party platforms such as Google, we use OAuth 2.0. Authentication happens on the provider's own secure sign-in screens, and Nacravo never sees or stores your Google password. OAuth tokens are stored encrypted, scoped to only the minimum permissions granted, and can be revoked at any time.
4. Google Cloud & Hosting
We rely on reputable cloud infrastructure for hosting and for the Google services we use to run our marketing and analytics. These providers maintain industry-recognised security certifications and protections at the infrastructure level, including physical security, network protection and platform hardening.
5. Role-Based Access & Least Privilege
Access to systems and data is granted on a least-privilege, need-to-know basis using role-based access controls (RBAC). Only authorised employees can access the tools required for their role, and access is reviewed and removed when no longer needed.
6. Password Protection
Accounts are protected with strong, unique passwords and, where available, multi-factor authentication (MFA). We never store third-party passwords, and we encourage staff to use a password manager.
7. Data Backup
Business-critical records are backed up so that we can recover from accidental loss or technical failure. Backups are protected with the same encryption and access controls as the primary data.
8. Logging & Monitoring
We log and monitor our website and connected services for errors, unusual activity and potential security issues, so that problems can be identified and addressed promptly.
9. Incident Response
If a security incident affecting personal data occurs, we will act quickly to contain and investigate it, remediate the cause, and notify affected individuals and the relevant authorities where required by UAE law. We keep records of incidents to strengthen our defences over time.
10. Security Contact
If you believe you have found a security vulnerability or have a security concern, please contact us so we can investigate. We appreciate responsible disclosure.
Questions about security?
Contact the Nacravo compliance team and we will respond within 30 days.
Nacravo LLC, Dubai, United Arab Emirates
Email: info@nacravo.com
Data Protection / Privacy Officer: info@nacravo.com
Phone / WhatsApp: +971 55 540 3038
Website: www.nacravo.com