Information Security Policy
Our commitment to protecting client and organizational information assets.
Confidentiality
Information is accessible only to authorized personnel with a legitimate need to know.
Integrity
Information is accurate, complete, and protected from unauthorized modification.
Availability
Information and systems are available to authorized users when required.
Risk Management
Security risks are identified, assessed, and managed to acceptable levels.
Scope
This policy applies to all Forterra Systems employees, contractors, and third-party service providers who have access to Forterra information systems and data.
Access Control
Access to systems and data is granted on a least-privilege basis. All access is authenticated using multi-factor authentication where applicable.
Data Encryption
All data in transit is encrypted using TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256 encryption.
Incident Response
Security incidents are reported, investigated, and resolved according to our incident response procedure. Clients are notified of incidents affecting their data within 72 hours.
Compliance
Forterra Systems aligns with ISO 27001 information security management principles and complies with the Kenya Data Protection Act, 2019.
Contact
Security concerns: info@forterra.co.ke