Security

Practical controls for resilient digital operations.

Our security approach connects people, technology and operating procedures across access, development, data protection, monitoring, incident response and recovery.

Security approach

Design for prevention while preparing for failure.

No platform can remove every risk. Responsible security combines preventive controls with visibility, response readiness and tested recovery procedures.

Controls should be proportionate to the system, data, users, integrations and potential impact rather than applied as a static checklist.

Security domains

Layered controls across the technology environment.

A dependable security programme reduces reliance on any single control by combining access, development, infrastructure, monitoring and recovery practices.

IAMControl domain

Identity and access

Access should follow role, responsibility and business need, with stronger authentication and additional approval for sensitive functions.

  • Role-based permissions
  • Authentication controls
  • Access review and removal
DATControl domain

Data protection

Data handling should consider classification, encryption, minimisation, retention and controlled access across its lifecycle.

  • Encryption in transit and at rest
  • Data minimisation
  • Retention and disposal rules
DEVControl domain

Secure development

Security requirements should be considered during design, implementation, review, testing, deployment and maintenance.

  • Code and dependency review
  • Environment separation
  • Change and release controls
INFControl domain

Infrastructure security

Cloud and hosting environments should use hardened configurations, controlled administration and appropriate network boundaries.

  • Configuration standards
  • Restricted administration
  • Environment monitoring
MONControl domain

Monitoring and detection

Operational logs and alerts help authorised teams identify unusual activity, service degradation and events requiring investigation.

  • Security-relevant logging
  • Operational alerting
  • Investigation records
RESControl domain

Resilience and recovery

Backups, recovery procedures and continuity planning help reduce the impact of service failures and security incidents.

  • Backup verification
  • Recovery procedures
  • Continuity planning

Secure development lifecycle

Security decisions begin before code reaches production.

Each stage of delivery should create evidence that important risks were considered, controls were implemented and the release was authorised.

  1. 01

    Define

    Identify data, access, abuse, availability and integration risks before implementation begins.

  2. 02

    Design

    Select proportionate controls and document important trust boundaries, permissions and failure paths.

  3. 03

    Build

    Use reviewed code, controlled dependencies, protected secrets and separated environments.

  4. 04

    Verify

    Test expected controls, failure conditions and release readiness before production deployment.

  5. 05

    Operate

    Monitor systems, manage access, address vulnerabilities and maintain reliable operational records.

  6. 06

    Improve

    Use incidents, reviews and technology changes to strengthen the next development cycle.

Incident readiness

A response process designed to protect evidence and restore safe operation.

Security events need clear authority, rapid coordination and accurate records. Preparation reduces uncertainty when time-sensitive decisions are required.

01

Prepare

Maintain roles, contact routes, decision authority, evidence procedures and relevant technical access before an incident occurs.

02

Identify

Confirm what happened, affected systems, potential impact and the information needed for immediate decisions.

03

Contain

Limit further impact while preserving evidence and avoiding unnecessary disruption to unaffected services.

04

Recover

Restore safe operation, validate critical functions and communicate through approved internal and external routes.

05

Learn

Document the root causes, control gaps, response quality and corrective actions with accountable owners.

Shared responsibility

Security depends on the full operating relationship.

The exact responsibility boundary varies by product and deployment model, but it should always be documented before production use.

01

Exotic Digital Group

  • Protect managed infrastructure and corporate systems
  • Apply approved access and development controls
  • Monitor supported environments and coordinate incident response
  • Maintain relevant backup, recovery and change procedures
02

Customers and partners

  • Protect their accounts, credentials and authorised users
  • Configure available controls appropriately
  • Provide accurate integration and contact information
  • Report suspected security issues through approved channels

Continuity and recovery

Backups are valuable only when restoration is understood and verified.

Recovery planning should identify critical services, dependencies, restoration order, responsible owners and the checks required before normal operation resumes.

Targets for availability, recovery time and data recovery should be approved for each relevant service rather than presented as universal guarantees.

Security contact

Report suspected vulnerabilities through an approved private channel.

Do not publish sensitive security details publicly. Until a dedicated disclosure channel is formally approved, use the corporate contact route and identify the matter as a security concern.

Open the contact page

Assurance claims

Publish only certifications and audit outcomes supported by current evidence.

Security certifications, penetration-test claims, uptime commitments, encryption statements and compliance attestations must be reviewed for scope, date and applicability before publication.

This page describes the intended control framework and should not be interpreted as a certification or independent assurance report.

Secure foundations

Connect security architecture to product, trust and compliance requirements.

Discuss platform security, deployment responsibility, operational resilience or incident readiness with the group.