TrackQUAL logo

Documentation

Information Security Policy

Created: 11 Mar 2026

Last updated: 25 Jun 2026

Security

This Information Security Policy describes the security governance and control framework used by Apperley Holdings Ltd. trading as TrackQUAL ("TrackQUAL", "we", "us", or "our") for the TrackQUAL platform and related services.

This policy is intended to provide a formal statement of TrackQUAL's security approach. It should be read alongside supporting policies and documents, including Incident Response, Availability/Backup/Incident Response, Data Protection and Data Flows, Privacy Policy, DPA, Retention and Deletion Policy, and Subprocessors documentation.

1. Document Metadata and Control

  • Document title: TrackQUAL Information Security Policy
  • Document owner: Founder/Director
  • Version: 1.0
  • Effective date: 25 June 2026
  • Review cadence: At least quarterly, plus ad hoc after significant incidents or material platform changes
  • Next scheduled review date: 25 September 2026

2. Purpose

The purpose of this policy is to define TrackQUAL's security principles, governance model, and high-level controls for protecting service confidentiality, integrity, and availability.

3. Scope

This policy applies to TrackQUAL's production platform and supporting operations, including identity and access controls, application and infrastructure security, data handling, monitoring and incident response, third-party service dependencies, and continuity/recovery practices.

4. Governance and Accountability

TrackQUAL is a founder-led business. Senior management has direct accountability for information security governance, risk treatment decisions, policy maintenance, and review of security performance.

Security responsibilities include:

  • policy and control ownership;
  • risk assessment and treatment oversight;
  • access governance and privileged access control;
  • incident triage, response, and follow-up improvement; and
  • supplier and subprocessor security governance.

5. Security Principles

TrackQUAL applies a defence-in-depth model guided by these principles:

  • least-privilege access wherever reasonably possible;
  • role-based and context-aware authorization controls;
  • tenant-aware segregation and controlled access boundaries;
  • secure-by-default service and configuration practices;
  • protection of confidentiality, integrity, and availability; and
  • continuous review and control improvement.

6. Access Control, Identity, and Authentication

TrackQUAL applies role-based access controls with additional fine-grained permissions and tenant/workspace/customer scoping controls. Access is granted based on business need and least privilege.

Authentication and account security controls include:

  • password policy and secure credential handling;
  • secure sign-in and session controls;
  • email verification and account lifecycle controls;
  • rate limiting and anti-abuse protections on auth flows; and
  • two-factor authentication capability where enabled.

7. Data Protection and Cryptography

TrackQUAL's security controls are aligned with its data protection framework and contractual commitments. At a high level:

  • data in transit is protected using TLS;
  • data at rest is protected through managed infrastructure/service controls where supported and configured;
  • encryption is applied as part of a layered security model rather than as a single control; and
  • processor/controller role handling is described in supporting privacy and contractual documentation.

8. Logging, Monitoring, and Incident Handling

TrackQUAL uses logging and monitoring to support operational reliability and security visibility. Security and operational events are reviewed for anomaly detection, investigation, and remediation.

TrackQUAL maintains an incident response process covering:

  • identification and triage;
  • containment and investigation;
  • recovery and remediation;
  • customer communications where relevant; and
  • post-incident review and improvement actions.

Where TrackQUAL acts as processor, personal data breach handling is also governed by the DPA and related contractual obligations.

9. Infrastructure Security and Resilience

TrackQUAL operates on managed cloud services with security hardening and resilience controls appropriate to platform risk and service context.

Current measures include:

  • restricted operational and administrative access paths;
  • managed hosting, storage, and database controls;
  • patching and maintenance practices;
  • backup and restore planning for key service components; and
  • operational escalation and recovery workflows.

10. Supplier and Subprocessor Security

TrackQUAL uses a defined set of suppliers/subprocessors to support delivery of the service. Provider use is subject to documented governance, contractual controls, and ongoing review. Current providers are documented on the Subprocessors page.

11. Risk Management and Formal Review

TrackQUAL maintains a formal risk assessment and treatment process supported by a live risk register and monitoring procedure. Risks are prioritized by likelihood and impact, assigned owners, and tracked to resolution or formally approved residual acceptance.

TrackQUAL conducts formal management review of the security program at least quarterly, with additional ad hoc reviews after significant incidents or material platform changes.

12. Exceptions and Policy Updates

Any exception to this policy must be approved by senior management, documented with rationale, and reviewed within a defined timeframe. This policy may be updated to reflect legal, technical, operational, or risk changes.

13. Contact and Assurance

If you require assurance information, evidence of control operation, or a security questionnaire response, contact TrackQUAL:

Apperley Holdings Ltd. trading as TrackQUAL
Company number: 15798690
Burcombe Road, Chalford, GL6 8BH
Email: info@trackqual.com
Telephone: 01453 374453

Available languages

EN-GBEN-US