Security Policy
Last updated: May 9, 2025
Torvanel Omi is committed to protecting the security of our platform, our users, and the data entrusted to us. This Security Policy describes the measures we take to safeguard information, the responsibilities of users, and the procedures we follow when security incidents occur. By accessing or using our services at torvanelomi.com, you acknowledge and agree to the practices described in this document.
1. Scope
This policy applies to all systems, services, and infrastructure operated by Torvanel Omi, including our website, online learning platform, workshop tools, interactive exercises, and any associated APIs or integrations. It covers all users, including registered participants, instructors, administrators, and visitors.
2. Our Security Commitments
We implement and maintain reasonable and appropriate technical and organizational measures designed to protect user data and platform integrity against unauthorized access, disclosure, alteration, or destruction.
2.1 Infrastructure Security
Our platform is hosted on infrastructure that applies industry-standard security controls. We use firewalls, intrusion detection mechanisms, and network segmentation to reduce exposure to external threats. Access to production environments is restricted to authorized personnel only.
2.2 Data Encryption
All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS). Sensitive data stored on our systems is encrypted at rest using recognized encryption standards. We do not store payment card details directly on our servers.
2.3 Access Control
We apply the principle of least privilege across our internal systems. Staff members are granted access only to the systems and data necessary to perform their roles. Multi-factor authentication is required for administrative access to critical systems. Access rights are reviewed periodically and revoked promptly when no longer required.
2.4 Vulnerability Management
We conduct regular reviews of our codebase and dependencies to identify and remediate known vulnerabilities. Security patches are applied in a timely manner. We perform periodic security assessments of our platform to identify weaknesses before they can be exploited.
2.5 Monitoring and Logging
Our systems maintain logs of access and activity for security monitoring purposes. Automated alerts are configured to detect anomalous behavior. Logs are retained for a defined period and protected against unauthorized modification.
2.6 Secure Development Practices
Security is integrated into our software development lifecycle. Our development team follows secure coding guidelines, conducts code reviews with security considerations, and tests new features for potential vulnerabilities before deployment.
2.7 Third-Party Services
Where we engage third-party service providers to process or store data on our behalf, we assess their security practices and require that they maintain appropriate safeguards. We enter into data processing agreements with such providers where applicable.
3. User Responsibilities
Security is a shared responsibility. Users of our platform are expected to take reasonable steps to protect their own accounts and data.
3.1 Account Credentials
You are responsible for maintaining the confidentiality of your login credentials. Choose a strong, unique password for your Torvanel Omi account and do not share it with others. If you suspect your credentials have been compromised, change your password immediately and contact us at support@torvanelomi.com.
3.2 Device and Network Security
Ensure that the devices you use to access our platform are protected with up-to-date operating systems, antivirus software, and security patches. Avoid accessing your account over unsecured or public Wi-Fi networks without using a trusted VPN.
3.3 Phishing and Social Engineering
Be cautious of unsolicited communications claiming to be from Torvanel Omi. We will never ask for your password via email or chat. If you receive a suspicious message appearing to come from us, do not click any links and report it to support@torvanelomi.com.
3.4 Acceptable Use
Users must not attempt to probe, scan, or test the vulnerability of our systems without prior written authorization. Unauthorized attempts to access systems, accounts, or data belonging to other users or to Torvanel Omi are strictly prohibited and may result in account suspension and legal action.
4. Incident Response
Despite our best efforts, no system can guarantee absolute security. In the event of a confirmed security incident, we follow a defined incident response process.
4.1 Detection and Containment
Upon detecting or being notified of a potential security incident, our team acts promptly to investigate, contain the impact, and prevent further exposure. Affected systems may be temporarily taken offline if necessary to protect user data.
4.2 Assessment and Remediation
We assess the scope and nature of the incident to determine what data or systems were affected. Root cause analysis is conducted and remediation steps are implemented to address identified weaknesses.
4.3 Notification
If a security incident results in unauthorized access to personal data and poses a risk to affected users, we will notify impacted individuals without undue delay. Notifications will include a description of the incident, the type of data involved, and the steps we are taking in response.
5. Responsible Disclosure
We welcome responsible disclosure of potential security vulnerabilities in our platform. If you believe you have identified a security issue, please report it to us promptly so we can investigate and address it.
To report a vulnerability, contact our security team at:
- Email: support@torvanelomi.com
- Subject line: Security Vulnerability Report
Please include a clear description of the issue, the steps required to reproduce it, and any supporting evidence. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate it. We will acknowledge receipt of your report and keep you informed of our progress.
We do not pursue legal action against individuals who report vulnerabilities in good faith and in accordance with this responsible disclosure process.
6. Data Retention and Deletion
We retain user data only for as long as necessary to provide our services and fulfill the purposes described in our Privacy Policy. When data is no longer required, it is securely deleted or anonymized. Users may request deletion of their personal data by contacting us at support@torvanelomi.com.
7. Business Continuity and Backup
We maintain backup procedures to support recovery of data and services in the event of a system failure, disaster, or security incident. Backups are stored securely and tested periodically to ensure they can be restored reliably. Our business continuity plans are reviewed and updated on a regular basis.
8. Cookies and Tracking Technologies
Our platform uses cookies and similar technologies to support functionality, analyze usage, and improve the user experience. These technologies do not introduce security vulnerabilities when used as intended. Users can manage cookie preferences through their browser settings. For further details, refer to our Cookie Policy.
9. Children's Data
Our platform is not directed at children under the age of 16. We do not knowingly collect personal data from minors. If we become aware that a minor has provided us with personal data without appropriate consent, we will take steps to delete that information promptly. If you believe a minor has submitted data to our platform, please contact us at support@torvanelomi.com.
10. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or legal obligations. When we make material changes, we will update the date at the top of this page and, where appropriate, notify registered users by email or through a notice on our platform. We encourage you to review this policy periodically.
11. Contact Us
If you have questions, concerns, or requests relating to this Security Policy or our security practices, please contact us through any of the following channels:
- Email: support@torvanelomi.com
- Phone: +380522221752
- Postal address: Chkalova St, 17, Kharkiv, Kharkiv Oblast, Ukraine, 61000
- Website: torvanelomi.com
We are committed to addressing your concerns promptly and transparently.