Skip to searchSkip to main content

Information Security Policy

How we protect our systems, data, and client information.


1. Purpose
Ostratto Ltd ("Ostratto", "we", "our", "us") is committed to protecting the confidentiality, integrity and availability of all information assets entrusted to us by our customers, employees, suppliers and other stakeholders.

This policy outlines our approach to information security across all business operations, systems and data processing activities. It establishes the principles and controls implemented to safeguard information against unauthorised access, disclosure, alteration, loss and destruction.

Information security forms part of our commitment to delivering reliable, secure and trusted services while meeting our legal, regulatory and contractual obligations.


2. Objectives
Our objectives are to:
  • Protect all information, including client, employee and company information, from unauthorised access, disclosure, alteration or destruction
  • Ensure information remains accurate, complete and available when required for legitimate business purposes
  • Maintain compliance with the UK GDPR, the Data Protection Act 2018 and other applicable legal, regulatory and contractual obligations
  • Reduce information security risks through appropriate technical and organisational controls
  • Promote security awareness, accountability and good security practices across all personnel
  • Prevent, detect, respond to and recover from information security incidents effectively
  • Continually improve our information security management processes and controls


3. Scope
This policy applies to all information handled by Ostratto, including data stored, transmitted or processed:
  • On company-owned devices, mobile devices and cloud platforms
  • Within third-party services or client systems accessed or managed by Ostratto
  • By employees, directors, contractors, consultants, temporary workers and authorised third parties working on behalf of Ostratto

This policy applies regardless of the format of the information, including:
  • Electronic records
  • Paper documents
  • Emails
  • Databases
  • Portable storage devices
  • Verbal communications

Every individual working on behalf of Ostratto is expected to comply with this policy.


4. Roles and Responsibilities
4.1 Managing Director. Overall responsibility for ensuring effective implementation and review of this policy.

4.2 All Employees and Contractors. Responsible for following this policy and reporting security concerns or incidents promptly.

4.3 Technical Consultants and Administrators. Ensure systems are securely configured, patched, and monitored in line with industry standards.


5. Information Classification
All information must be handled according to its sensitivity:

a) Unclassified - This is information that can be made public without any implications for the company, such as information that is already in the public domain

b) Employee confidential - This includes information such as medical records, pay and so on

c) Company confidential - Such as contracts, source code, business plans, passwords for critical IT systems, client contact records, accounts etc

d) Client confidential - This includes personally identifiable information such as name or address, passwords to client systems, client business plans, new product information, market sensitive information etc



6. Data Protection
Personal data is processed lawfully, fairly and transparently in accordance with applicable data protection legislation and our Privacy Policy.

Ostratto implements appropriate technical and organisational measures to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Access to personal data is granted only to authorised personnel who require access to perform their duties.

Where Ostratto processes personal data on behalf of customers, appropriate contractual arrangements, including Data Processing Agreements where required, shall be maintained.

Personal data shall be retained only for as long as necessary and disposed of securely when no longer required.


7. Access Control
Access to systems is managed in accordance with the principle of least privilege.

Access rights are:
  • Approved before being granted
  • Restricted to authorised users
  • Reviewed periodically
  • Removed promptly when no longer required

In addition:
  • Strong and unique passwords must be used
  • Multi-factor authentication shall be enabled wherever supported, particularly for administrative and business-critical systems
  • Shared credentials are prohibited except where technically unavoidable and appropriately controlled
  • Privileged access shall be limited to authorised personnel only


8. System and Network Security
Ostratto maintains appropriate technical controls to protect company and customer systems.

This includes:
  • Secure configuration of devices and cloud services
  • Prompt installation of security updates and patches
  • Endpoint protection on managed devices
  • Use of firewalls where appropriate
  • Encryption of data in transit using industry-standard protocols (e.g. ISO 27001, SOC 2) where supported
  • Secure remote access methods
  • Ongoing monitoring of critical systems where appropriate

Cloud services used to deliver services should demonstrate recognised security standards and appropriate compliance certifications where available.


9. Physical Security
Reasonable physical safeguards are implemented to protect company assets and confidential information.

This includes:
  • Secure office access
  • Protection of workstations and portable devices
  • Secure storage of confidential documents
  • Disposal of confidential waste using appropriate methods

Portable devices should use device encryption where supported and must never be left unattended in unsecured locations.

Personnel working remotely are expected to maintain an appropriate level of physical security within their working environment.


10. Incident Management
  • All suspected or actual information-security incidents must be reported immediately to the Managing Director or IT Security Lead
  • Incidents will be logged, investigated, and resolved following our incident-response procedure
  • Where required, affected clients and the Information Commissioner’s Office (ICO) will be notified in accordance with legal requirements


11. Training and Awareness
Ostratto promotes a culture of security awareness throughout the organisation.

All employees and contractors receive appropriate information security guidance during onboarding together with periodic reminders and updates.

Personnel are expected to remain vigilant against phishing, social engineering and other cyber security threats and to report any suspicious activity immediately.

Additional training may be provided where individuals process particularly sensitive information or administer customer systems.


12. Third-Party and Supplier Security
Suppliers who process information or provide technology services are expected to maintain security controls appropriate to the services they provide.

Where appropriate, Ostratto undertakes due diligence before engaging suppliers and reviews supplier suitability periodically.

Contracts with suppliers handling confidential or personal information should include appropriate confidentiality, privacy and information security obligations.


13. Data Backup and Recovery
  • Data is backed up regularly and stored securely in encrypted form
  • Backups are tested periodically to verify recoverability
  • In the event of data loss or corruption, recovery will be prioritised based on business impact


14. Continuous Improvement
We continually review our security controls to address emerging risks, technological change, and business growth.

Lessons learned from incidents and audits are incorporated into updated security procedures.


15. Review
This policy shall be reviewed at least annually, or sooner where required due to:
  • Changes in legislation or regulation
  • Significant business changes
  • Major security incidents
  • New technologies
  • Changes to customer or contractual requirements

The Managing Director is responsible for ensuring this policy remains accurate, appropriate and effective.