Security Approach
IM Technologies focuses on building and supporting secure, maintainable, and governance-aware digital systems. Our work is informed by recognized security, privacy, and governance standards where appropriate.
References to ISO/IEC 27001, NIST Cybersecurity Framework, CIS Controls, OWASP, and the Data Privacy Act of 2012 are used as practical guides. They do not state or imply certification, accreditation, or a guarantee that every engagement meets every requirement of those frameworks.
Security by Design
We aim to consider security early in planning, architecture, development, deployment, and maintenance. This includes defining appropriate controls, reducing unnecessary complexity, documenting important decisions, and aligning implementation with realistic business risks. We also seek to reduce attack surface, eliminate unnecessary functionality, and promote secure defaults wherever practical.
Privacy by Design
We consider privacy requirements when designing systems that collect, store, process, or transmit personal data. This includes data minimization, access control, purpose limitation, retention awareness, and safeguards appropriate to the context of the system and the client engagement.
Privacy-related concerns and data subject rights requests should be sent to privacy@imtechnologies.ph.
Secure Development Practices
Secure development practices may include input validation, output encoding, prepared statements where applicable, CSRF protection for state-changing actions, secure session handling, least-privilege access, dependency review, secure dependency management, code review, environment separation, configuration hardening, vulnerability remediation, audit logging, and careful handling of credentials and secrets.
Access Control Principles
We favor least privilege, role-appropriate access, separation of duties where practical, secure authentication patterns, and periodic review of access rights. Access should be granted only to people or systems with a legitimate need.
Infrastructure and Hosting Security
For infrastructure and hosting work, we consider secure configuration, timely security patch management, TLS encryption where appropriate, backups where appropriate, monitoring needs, environment isolation, secure deployment practices, and responsible management of cloud or hosting credentials.
Monitoring and Logging
Logging and monitoring are used to support reliability, troubleshooting, and security visibility. Logs are handled with appropriate safeguards, retained only for as long as reasonably necessary, and reviewed in accordance with operational needs, contractual commitments, and applicable legal requirements.
Incident Response
IM Technologies maintains processes appropriate to its size and services for identifying, assessing, responding to, and recovering from security incidents. Response activities may include investigation, containment, remediation, recovery, documentation, and communication with affected parties where appropriate and required by law.
Vulnerability Handling
When vulnerabilities are identified in systems we build or support, we work to assess severity, understand impact, prioritize remediation, and communicate responsibly with relevant stakeholders. Remediation timelines depend on scope, severity, ownership, and operational constraints. Where appropriate, vulnerabilities may be tracked through a documented remediation process until resolved or formally accepted.
Responsible Disclosure Contact
If you believe you have found a security issue involving an IM Technologies website, product, or service, contact us at security@imtechnologies.ph. Please include a clear description, affected URL or system, steps to reproduce, impact, and your contact details.
IM Technologies encourages coordinated and responsible disclosure of security vulnerabilities. Do not access, modify, delete, exfiltrate, or disrupt data or systems. Do not perform denial-of-service testing, social engineering, phishing, spam, or testing against third-party systems without authorization. Abuse, phishing, spam, and misuse reports should be sent to abuse@imtechnologies.ph.
Limitations and Transparency
Security is an ongoing process, not a one-time claim. No website, software, network, or operational process can be guaranteed to be completely secure. We aim to be practical and transparent about risks, responsibilities, and limitations.
Continuous Improvement
As IM Technologies grows, we expect our controls, documentation, processes, and product security practices to mature. We continuously evaluate and improve our security practices as our services evolve and as risks, client needs, and regulatory expectations change. This Security Statement may be updated periodically to reflect those changes.
Contact
For security questions, responsible disclosure, vulnerability reports, and security concerns, contact IM Technologies at security@imtechnologies.ph.