Security Policy
Last updated: July 28, 2025
Pesk Wadrun is committed to protecting the security of our platform, our users, and the data entrusted to us. This Security Policy describes the measures we take to safeguard information, the responsibilities of users, and how we respond to security incidents. By using our services at peskwadrun.com, you acknowledge and agree to the practices described in this document.
1. Scope
This policy applies to all systems, infrastructure, and services operated by Pesk Wadrun, including our website, online learning platform, user accounts, and any associated applications. It covers all data processed, stored, or transmitted through our services, as well as the conduct of users and staff who interact with those systems.
2. Data Protection Principles
We apply the following core principles when handling user data and platform resources:
- Confidentiality: Access to sensitive information is restricted to authorized individuals only.
- Integrity: Data is protected from unauthorized modification or corruption.
- Availability: Systems and data are maintained to ensure reliable access for authorized users.
- Accountability: Actions taken within our systems are logged and attributable to identifiable actors.
3. Infrastructure Security
3.1 Network and Hosting
Our platform is hosted on infrastructure that employs industry-standard security controls. Network traffic is segmented and monitored. Firewalls and access control lists restrict inbound and outbound connections to only those required for legitimate service operation.
3.2 Encryption in Transit
All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS). We enforce the use of current, supported TLS versions and disable deprecated or insecure cipher suites. Connections over unencrypted protocols are redirected to encrypted equivalents.
3.3 Encryption at Rest
Sensitive data stored within our systems, including user credentials and personal information, is encrypted at rest using accepted cryptographic standards. Encryption keys are managed separately from the data they protect and are rotated on a defined schedule.
3.4 System Hardening
Servers and services are configured according to hardening guidelines. Unnecessary services, ports, and software components are disabled or removed. Operating systems and third-party dependencies are kept up to date with security patches applied in a timely manner.
4. Access Control
4.1 Principle of Least Privilege
Access to systems, databases, and administrative tools is granted on a need-to-know basis. Users and internal staff receive only the minimum level of access required to perform their intended functions. Access rights are reviewed periodically and revoked when no longer necessary.
4.2 Authentication Requirements
Administrative and privileged accounts require strong authentication, including multi-factor authentication where technically feasible. Shared credentials are not permitted for sensitive systems. Session tokens are issued with defined expiration periods and invalidated upon logout or detected anomalies.
4.3 User Account Security
User accounts are protected by password requirements that enforce minimum length and complexity. Passwords are stored using one-way cryptographic hashing with salting. Users are encouraged to choose unique passwords and to avoid reusing credentials across services.
5. Application Security
5.1 Secure Development Practices
Security considerations are incorporated throughout our development lifecycle. Code is reviewed for common vulnerabilities before deployment. We follow established guidelines for secure coding to mitigate risks including injection attacks, cross-site scripting, cross-site request forgery, and insecure direct object references.
5.2 Input Validation and Output Encoding
All user-supplied input is validated and sanitized before processing. Output rendered in the browser is encoded appropriately to prevent script injection. File uploads are restricted by type and size and are scanned before being stored or served.
5.3 Dependency Management
Third-party libraries and components used in our platform are tracked and monitored for known vulnerabilities. Affected dependencies are updated or replaced promptly when security advisories are issued.
6. Monitoring and Logging
Our systems maintain logs of authentication events, administrative actions, and significant application activity. Logs are stored securely and retained for a defined period sufficient to support incident investigation. Automated monitoring is in place to detect unusual patterns, repeated failures, or indicators of unauthorized access. Alerts are reviewed by responsible personnel on a regular basis.
7. Incident Response
7.1 Detection and Containment
When a potential security incident is identified, we act promptly to assess its nature and scope. Affected systems or accounts may be isolated or suspended to prevent further impact while an investigation is conducted.
7.2 Investigation and Remediation
Confirmed incidents are investigated to determine root cause, affected data, and the extent of any unauthorized access or disclosure. Vulnerabilities that contributed to the incident are remediated before affected systems are returned to normal operation.
7.3 Notification
Where an incident results in unauthorized access to user data, affected users will be notified in a timely manner through available contact channels. Notifications will describe the nature of the incident, the type of data involved, and the steps being taken in response. We will also fulfill any applicable notification obligations to relevant authorities.
8. User Responsibilities
Users of our platform share responsibility for maintaining the security of their accounts and interactions. You are expected to:
- Keep your login credentials confidential and not share them with others.
- Use a strong, unique password for your account.
- Log out of your account when using shared or public devices.
- Report any suspected unauthorized access to your account promptly.
- Avoid attempting to access systems, accounts, or data that you are not authorized to access.
- Refrain from uploading or transmitting malicious code, scripts, or files through our platform.
Failure to observe these responsibilities may result in account suspension or termination.
9. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities discovered in our platform. If you believe you have identified a security issue, please contact us at support@peskwadrun.com with a clear description of the issue, steps to reproduce it, and any relevant supporting information. We ask that you refrain from publicly disclosing the issue until we have had a reasonable opportunity to investigate and address it. We will acknowledge receipt of valid reports and keep you informed of our progress.
10. Third-Party Services
Our platform may integrate with or rely upon third-party services for functions such as payment processing, analytics, or content delivery. These services are selected with attention to their own security practices. However, we do not control third-party systems and are not responsible for their security posture. Users are encouraged to review the security and privacy policies of any third-party services they interact with through our platform.
11. Business Continuity and Backups
Critical data and configurations are backed up on a regular schedule. Backups are stored securely and tested periodically to verify that restoration is possible. In the event of a significant service disruption, we maintain procedures to restore operations within a defined recovery timeframe.
12. Physical Security
Our services operate within data center environments that maintain physical access controls, including restricted entry, surveillance, and environmental protections such as fire suppression and climate control. Physical access to server infrastructure is limited to authorized personnel of the relevant facility operators.
13. Policy Review and Updates
This Security Policy is reviewed periodically and updated to reflect changes in our practices, technology, or applicable requirements. When material changes are made, the updated policy will be published on this page with a revised effective date. Continued use of our services following the publication of changes constitutes acceptance of the updated policy.
14. Contact
If you have questions about this Security Policy or wish to report a security concern, please contact us:
- Email: support@peskwadrun.com
- Phone: +380 53 676 35 27
- Address: Shchyretska St, 36/12, Lviv, Lviv Oblast, Ukraine, 79000