Our approach
Security is part of how Sectem plans, builds, and operates technology and managed services. We assess risk in context and align safeguards with the systems involved, the sensitivity of information, client requirements, and applicable law.
This page is a high-level overview, not a certification, warranty, or complete description of every control. Project-specific controls and responsibilities are documented during scoping and in the applicable written agreement.
Governance and responsibility
Security responsibilities are assigned across technical and operational teams. Relevant requirements are considered during solution design, delivery planning, vendor selection, access decisions, and incident handling.
Personnel are expected to follow confidentiality, acceptable-use, and data-handling requirements appropriate to their role and engagement.
Identity and access
Sectem applies role-appropriate access principles designed to limit systems and information to people who need them for authorized work. Depending on the environment, safeguards may include unique accounts, multi-factor authentication, managed permissions, access reviews, and prompt removal or adjustment of access when responsibilities change.
Data protection
We seek to minimize unnecessary data collection and use safeguards appropriate to the sensitivity and purpose of information. Depending on the service and platform, protections may include encrypted transmission, provider-managed encryption at rest, controlled sharing, backups, retention rules, and secure deletion procedures.
Clients remain responsible for identifying special data categories, regulatory requirements, retention needs, and access constraints before sharing information with Sectem.
Secure delivery
For software and platform engagements, security is considered throughout planning, implementation, review, and release. Practices are selected for the project and may include peer review, dependency management, environment separation, secrets handling, testing, change control, and remediation of identified issues.
Infrastructure and providers
Sectem uses established cloud, hosting, communications, and business service providers where appropriate. Providers are evaluated according to their role and the information involved. Client-specific infrastructure choices, regions, configurations, and third-party responsibilities are agreed as part of the engagement.
Monitoring and incident response
Sectem maintains processes designed to identify, assess, contain, investigate, and recover from suspected security events. Monitoring and logging depend on the relevant platform and engagement.
When a confirmed incident affects client information, notification and cooperation are handled according to applicable law and contractual commitments.
Report a security concern
If you believe you have found a security issue involving Sectem’s Website or systems, email legal@sectem.com with a clear description, the affected location, and steps needed to reproduce the issue. Do not access, alter, download, or disclose data that does not belong to you, disrupt services, use social engineering, or conduct destructive testing.
We will review good-faith reports and route them to the appropriate owner. This reporting channel does not authorize testing and is not a public bug-bounty program.

