ISO/IEC 27001 / Management framework
This security policy uses the ISO/IEC 27001 information security management framework as a reference. The controls, implementation status, and verification scope for a specific engagement are defined in the project documentation and agreement. This statement does not claim third-party ISO/IEC 27001 certification.
GDPR / Applicable data protection requirements
Where GDPR applies, processing design considers purpose limitation, data minimization, transparency, retention, and individual rights. Contracts define the roles and responsibilities of the customer and service providers.
Security controls and project responsibilities
Depending on the engagement, controls may include role-based access, encrypted transport, backup arrangements, operational logs, and incident handling. Deployment locations, suppliers, validation requirements, and service commitments are agreed within the project scope.
Security enquiries
Contact info@newgens.org to discuss security requirements or report a concern. Describe the issue without including credentials or unnecessary customer data.