Policy

Data Security Policy

Illume security practices for CMS content, admin accounts, media assets, contact submissions, and product delivery data.

Effective: 6 May 2026Last reviewed: 6 May 2026

Security baseline

Illume uses role-based admin access, hashed passwords, HTTPS, protected API routes, environment-managed secrets, database backups, logging, and least-privilege operational access where practical.

Production infrastructure should use secure reverse proxy configuration, SSL certificates, firewall controls, and restricted administrative access.

Incident handling

Security incidents are triaged for scope, impact, containment, recovery, and notification obligations.

Where applicable, incident reporting and log retention should consider CERT-In directions, contractual duties, and client-specific notification requirements.

Data retention

Contact submissions, project records, invoices, and CMS audit information are retained only as long as required for business, legal, security, tax, and contractual purposes.

Deletion requests are assessed against legal retention needs and active service obligations.