Legal

Information Security Policy

Our commitment to protecting client and organizational information assets.

Confidentiality

Information is accessible only to authorized personnel with a legitimate need to know.

Integrity

Information is accurate, complete, and protected from unauthorized modification.

Availability

Information and systems are available to authorized users when required.

Risk Management

Security risks are identified, assessed, and managed to acceptable levels.

Scope

This policy applies to all Forterra Systems employees, contractors, and third-party service providers who have access to Forterra information systems and data.

Access Control

Access to systems and data is granted on a least-privilege basis. All access is authenticated using multi-factor authentication where applicable.

Data Encryption

All data in transit is encrypted using TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256 encryption.

Incident Response

Security incidents are reported, investigated, and resolved according to our incident response procedure. Clients are notified of incidents affecting their data within 72 hours.

Compliance

Forterra Systems aligns with ISO 27001 information security management principles and complies with the Kenya Data Protection Act, 2019.

Contact

Security concerns: info@forterra.co.ke