Legal document
Information Security Policy
How Desklly protects the confidentiality, integrity, and availability of the information entrusted to us.
1. Scope
This policy applies to all Desklly personnel, contractors, systems, and third parties that process Desklly or customer data.
2. Framework
Our security programme is aligned with the NHS Data Security and Protection Toolkit (DSPT), Cyber Essentials, ISO/IEC 27001, and the National Cyber Security Centre (NCSC) Cloud Security Principles.
3. Governance
A named Information Security Lead owns this policy. The policy is reviewed at least annually and after any material change or incident. Roles and responsibilities are documented and communicated to all staff.
4. Access control
Least-privilege access, role-based access control, unique named accounts, mandatory multi-factor authentication (MFA) on all administrative interfaces, quarterly access reviews, and immediate deprovisioning on leaver events.
5. Encryption
TLS 1.2 or higher for all data in transit, including telephony (SRTP where the carrier supports it). AES-256 for data at rest. Keys are managed by the cloud provider's KMS with rotation.
6. Network and infrastructure
Segregated environments (development, staging, production). Production access is restricted to a hardened bastion with MFA. All infrastructure changes are code-reviewed and version-controlled.
7. Vulnerability management
Automated dependency and container scanning on every deploy. Critical vulnerabilities are remediated within 7 days, high within 30 days. Independent penetration testing is carried out annually and after major changes.
8. Logging and monitoring
Security-relevant events are centrally logged, retained for at least 12 months, and monitored for anomalies. Alerts are triaged 24/7 by the on-call engineer.
9. People security
All personnel undergo background screening appropriate to their role, sign a confidentiality agreement, and complete annual data protection and security training including phishing simulations.
10. Supplier security
All sub-processors are risk-assessed before engagement and reviewed annually. Contracts include GDPR Article 28 terms and security obligations.
11. Incident response
Security incidents are managed under the Incident Response Plan. Personal data breaches are notified to controllers within 24 hours of confirmation.
12. Physical security
Desklly does not operate its own data centres. Production workloads run in ISO 27001 / SOC 2 certified cloud regions in the UK/EEA.
