Protection Research

Information Security Policy

Effective Date: 3 August 2026

Contents

  • Purpose
  • Scope
  • Information Security Objectives
  • Governance and Responsibilities
  • Information Assets
  • Risk Management
  • Access Control
  • Authentication and Password Management
  • Encryption
  • Secure Development
  • Vulnerability Management
  • Logging and Monitoring
  • Incident Management
  • Backup and Recovery
  • Supplier Security
  • Staff Responsibilities
  • Policy Review
  • Contact

1. Purpose

The purpose of this Information Security Policy ("Policy") is to define the principles and controls implemented by Protection Research Ltd ("Protection Research", "we", "our" or "us") to protect the confidentiality, integrity and availability of our information, systems and Services.

This Policy supports our commitment to:

  • protecting customer information
  • maintaining secure and resilient Services
  • reducing cyber security risks
  • complying with legal and regulatory obligations
  • supporting business continuity; and

promoting a culture of information security throughout the organisation.

This Policy should be read alongside our:

Terms of Service;

Privacy Policy;

Data Processing Agreement;

Acceptable Use Policy; and

Business Continuity & Disaster Recovery Policy.

2. Scope

This Policy applies to all information assets owned, managed or processed by Protection Research, including: customer information; research data; software applications; source code; cloud infrastructure; internal documentation; business records; websites; development environments; production environments; communication systems; and any supporting technology used to deliver our Services. This Policy applies to all directors, employees, contractors and any other individuals authorised to access Protection Research systems or information. Third-party service providers are expected to maintain security standards appropriate to the services they provide.

3. Information Security Objectives

Protection Research aims to:

  • protect the confidentiality of customer and company information
  • preserve the integrity and accuracy of information
  • maintain the availability and resilience of critical systems
  • minimise cyber security risks through appropriate technical and organisational controls
  • detect, investigate and respond to security incidents
  • continually improve our security posture
  • support compliance with Applicable Laws; and

maintain the trust of our customers and business partners. Information security is considered an ongoing process requiring continual assessment and improvement.

4. Governance and Responsibilities

Protection Research recognises that effective information security requires clear governance and accountability. The Company is responsible for: establishing security policies; maintaining appropriate security controls; reviewing security risks; ensuring compliance with applicable legal obligations; investigating security incidents; and promoting continuous improvement.

Every individual with authorised access to Protection Research systems is responsible for:

  • complying with this Policy
  • protecting confidential information
  • safeguarding authentication credentials
  • reporting suspected security incidents promptly; and

using company systems responsibly. Security responsibilities apply regardless of whether access is provided remotely or from company-controlled locations.

5. Information Assets

Protection Research identifies and manages information assets appropriate to the operation of the business.

Information assets may include:

  • customer information
  • research publications
  • technical documentation
  • source code
  • databases
  • intellectual property
  • authentication systems
  • operational records
  • financial records; and

cloud infrastructure.

Information assets should be:

  • appropriately protected
  • accessible only to authorised individuals
  • retained only for as long as necessary; and

securely disposed of when no longer required. Protection measures should reflect the sensitivity and business value of each asset.

6. Risk Management

Protection Research adopts a risk-based approach to information security. Security risks are identified, assessed and managed to reduce the likelihood and impact of security incidents affecting our Services, customers or business operations.

Risk management activities include:

  • identifying information assets
  • assessing potential threats and vulnerabilities
  • evaluating business impact
  • implementing proportionate security controls
  • reviewing changes to systems and infrastructure
  • monitoring emerging cyber security threats; and

periodically reviewing the effectiveness of implemented controls. Security controls are selected based on the nature of the risks presented and the sensitivity of the information being protected. Risk assessments are reviewed periodically and whenever significant changes occur to our systems, Services or operating environment.

7. Access Control

Access to Protection Research systems and information is granted on the principle of least privilege. Users are provided with only the level of access necessary to perform their authorised responsibilities.

Access control measures include:

  • unique user accounts
  • role-based access permissions where appropriate
  • approval processes for privileged access
  • periodic review of user permissions
  • prompt removal of unnecessary access
  • secure account provisioning and deprovisioning; and

protection against unauthorised access. Administrative privileges are restricted to authorised individuals and are granted only where operationally necessary. Access rights are reviewed following changes in employment status, job responsibilities or contractual relationships.

8. Authentication and Password Management

Protection Research requires appropriate authentication measures to protect access to systems and information. Authentication controls include, where appropriate: strong password requirements; multi-factor authentication for administrative accounts and critical services where supported; secure password storage using industry-standard cryptographic techniques; protection against brute-force attacks; account lockout or other protective mechanisms where appropriate; secure credential management; and prompt revocation of compromised credentials. Users are responsible for maintaining the confidentiality of their authentication credentials and must not share passwords or authentication tokens with unauthorised individuals. Suspected credential compromise should be reported immediately.

9. Encryption

Protection Research uses encryption to protect information during transmission and, where appropriate, while stored.

Encryption measures may include:

Transport Layer Security (TLS) for data transmitted over public networks;

  • encryption of sensitive data at rest where appropriate
  • secure key management practices
  • encrypted backups where practicable
  • encryption of administrative communications where appropriate; and

secure disposal of encryption keys when no longer required. Cryptographic controls are reviewed periodically to reflect recognised industry standards and evolving security practices.

10. Secure Development

Protection Research is committed to developing and maintaining software using secure development practices. Our development processes aim to: incorporate security throughout the software development lifecycle; minimise common software vulnerabilities; review code before deployment where appropriate; manage software dependencies responsibly; apply security updates in a timely manner; test systems prior to production deployment where practicable; separate development and production environments where appropriate; and maintain appropriate change management procedures. Where vulnerabilities are identified, they are assessed and prioritised according to their potential impact and remediated as appropriate. Security considerations form part of ongoing product design, implementation and maintenance.

11. Vulnerability Management

Protection Research maintains processes to identify, assess and remediate security vulnerabilities affecting our systems and Services. Our vulnerability management activities may include: continuous monitoring of security advisories and threat intelligence; routine vulnerability assessments; security testing where appropriate; timely application of security updates and patches; prioritisation of vulnerabilities according to risk; verification of remediation activities; and periodic review of vulnerability management procedures. Where appropriate, Protection Research may engage with external security researchers through our Responsible Vulnerability Disclosure Policy. Critical vulnerabilities are prioritised for remediation based on their potential impact on the confidentiality, integrity or availability of our Services.

12. Logging and Monitoring

Protection Research maintains logging and monitoring capabilities appropriate to the operation of our Services.

Logging may include:

  • authentication events
  • administrative actions
  • security-related system events
  • application events
  • infrastructure events
  • error conditions; and

other operational activities necessary to support security monitoring.

Logs are used to:

  • investigate security incidents
  • detect suspicious activity
  • support operational troubleshooting
  • improve service reliability; and

assist with legal or regulatory obligations where applicable. Access to log data is restricted to authorised personnel and retained only for as long as reasonably necessary or as required by law.

13. Incident Management

Protection Research maintains procedures for responding to information security incidents. Our incident management process includes, where appropriate: identification of security events; assessment and classification; containment; investigation; eradication of identified threats; recovery of affected systems; communication with affected customers where appropriate; and post-incident review to identify opportunities for improvement. Where a personal data breach occurs, Protection Research will respond in accordance with applicable data protection legislation and the commitments set out in our Privacy Policy and Data Processing Agreement. Lessons learned from security incidents are used to strengthen our security controls and operational processes.

14. Backup and Recovery

Protection Research implements backup and recovery procedures designed to support the resilience of our Services. Our approach includes, where appropriate: regular backups of critical business data; secure storage of backup data; protection of backup integrity; periodic testing of restoration procedures; recovery planning for critical systems; and review of backup arrangements as our Services evolve. Backup strategies are designed to reduce the impact of accidental data loss, system failure and other operational disruptions. Detailed disaster recovery procedures are maintained separately within our Business Continuity & Disaster Recovery Policy.

15. Supplier Security

Protection Research recognises that third-party suppliers play an important role in the delivery of our Services. Where appropriate, we seek to engage suppliers that maintain security practices consistent with the nature of the services they provide.

Supplier security considerations may include:

  • security reputation
  • contractual obligations
  • data protection compliance
  • access controls
  • incident notification procedures
  • business continuity arrangements; and

ongoing performance and risk reviews. Suppliers that process personal data on our behalf are subject to appropriate contractual safeguards in accordance with applicable data protection laws.

16. Staff Responsibilities

Every individual authorised to access Protection Research systems has a responsibility to protect company and customer information.

Individuals are expected to:

  • comply with this Policy and related security procedures
  • protect confidential information
  • use company systems responsibly
  • maintain the security of authentication credentials
  • report suspected security incidents promptly
  • protect company equipment and devices
  • comply with applicable legal and contractual obligations; and

participate in security awareness activities where appropriate. Failure to comply with this Policy may result in the removal of system access, contractual action or other appropriate measures.

17. Policy Review

This Policy is reviewed periodically to ensure that it remains appropriate to:

  • our business operations
  • technological developments
  • evolving cyber security threats
  • legal and regulatory requirements; and

recognised industry good practice. Protection Research may update this Policy at any time. The most current version will be made available through our website or otherwise provided upon request.

18. Contact

Questions regarding this Information Security Policy should be directed to:

Protection Research Ltd

Company Number: 17366537

  • Registered Office: 41 Colwyn Road, Stockport, Cheshire, England, SK7 2JG
  • Email: support@protectionresearch.com

End of Information Security Policy

Effective Date: 3 August 2026

© Protection Research Ltd. All rights reserved.