Security Policy
Last updated: April 16, 2026
Pulevou is committed to protecting the security of its platform, services, and the data entrusted to us by our users. This Security Policy describes the technical and organisational measures we implement to safeguard information processed through pulevou.com and associated services.
1. Scope
This policy applies to all systems, infrastructure, applications, and processes operated by Pulevou that store, transmit, or process user data. It covers all individuals who access or interact with our platform, including registered learners, visitors, and administrative personnel.
2. Data Protection Principles
We apply the following core principles to all data we handle:
- Confidentiality: Access to data is restricted to authorised individuals with a legitimate operational need.
- Integrity: Data is protected against unauthorised modification, corruption, or deletion.
- Availability: Systems and services are maintained to ensure reliable access for authorised users.
- Accountability: Actions affecting data are logged and attributable to identifiable actors or processes.
3. Infrastructure Security
3.1 Hosting and Network
Our services are hosted on infrastructure provided by reputable cloud providers that maintain recognised industry certifications. Network traffic is segmented, and access between internal components is governed by firewall rules and access control lists. Unnecessary ports and services are disabled by default.
3.2 Encryption in Transit
All data transmitted between users and our platform is encrypted using TLS 1.2 or higher. Unencrypted HTTP connections are automatically redirected to HTTPS. We do not support deprecated cipher suites or protocol versions.
3.3 Encryption at Rest
Sensitive data stored within our systems is encrypted at rest using industry-standard encryption algorithms. Database backups and file storage are subject to the same encryption requirements.
3.4 System Hardening
Operating systems and application environments are configured according to hardening guidelines. Default credentials are removed, unnecessary services are disabled, and system components are regularly reviewed for configuration drift.
4. Access Control
4.1 Principle of Least Privilege
Access rights are granted based on the minimum level required to perform a given function. Permissions are reviewed periodically and revoked promptly when no longer required.
4.2 Authentication
Internal administrative access to production systems requires strong authentication. Where technically feasible, multi-factor authentication is enforced for accounts with elevated privileges. Shared credentials are not permitted.
4.3 User Account Security
User accounts on the platform are protected by password requirements that enforce minimum length and complexity. Passwords are stored using a one-way cryptographic hashing algorithm with a per-record salt. Plaintext passwords are never stored or transmitted.
4.4 Session Management
Authenticated sessions are issued with time-limited tokens. Sessions are invalidated upon logout and expire automatically after a defined period of inactivity. Session identifiers are rotated following authentication events.
5. Application Security
5.1 Secure Development Practices
Security considerations are integrated throughout the development lifecycle. Code changes are reviewed before deployment. We apply protections against common application-layer vulnerabilities including, but not limited to, injection attacks, cross-site scripting, cross-site request forgery, and insecure direct object references.
5.2 Dependency Management
Third-party libraries and software dependencies are monitored for known vulnerabilities. Updates and patches are applied in a timely manner. Dependencies that are no longer maintained or that present unacceptable risk are replaced.
5.3 Input Validation
All user-supplied input is validated and sanitised before processing. Output encoding is applied to prevent injection of malicious content into rendered pages or data responses.
5.4 Security Testing
We conduct periodic security assessments of our platform and infrastructure. Identified vulnerabilities are prioritised and remediated according to their severity. Critical issues are addressed on an expedited basis.
6. Monitoring and Logging
System events, authentication attempts, and administrative actions are logged to a centralised logging facility. Logs are retained for a defined period and are protected against unauthorised modification. Alerts are configured to notify responsible personnel of anomalous activity, potential intrusions, or system errors that may indicate a security concern.
7. Vulnerability Management
We maintain a process for identifying, assessing, and remediating security vulnerabilities across our systems. Severity ratings are assigned based on potential impact and exploitability. Patches for critical vulnerabilities are applied as a priority. We monitor public vulnerability disclosures relevant to the technologies we use.
8. Incident Response
8.1 Detection and Response
We maintain documented procedures for responding to security incidents. Upon detection of a suspected or confirmed incident, responsible personnel are notified and an investigation is initiated. Containment, eradication, and recovery steps are followed in accordance with the severity of the event.
8.2 Notification
In the event of a security incident that affects user data, we will notify affected individuals in accordance with applicable legal obligations and within a reasonable timeframe. Notifications will describe the nature of the incident, the data involved, and the steps taken in response.
8.3 Post-Incident Review
Following resolution of a security incident, a review is conducted to identify root causes, assess the effectiveness of the response, and implement measures to reduce the likelihood of recurrence.
9. Third-Party Services
We use third-party service providers to support the delivery of our platform, including payment processing, analytics, and infrastructure services. Providers are selected based in part on their security posture and are subject to contractual obligations regarding data protection. We do not sell user data to third parties.
Third-party integrations are reviewed for security implications before being introduced into the platform environment. Access granted to third parties is limited to what is necessary for the specific service being provided.
10. Data Backup and Recovery
Critical data is backed up on a regular schedule. Backups are stored in a manner that is logically or physically separate from primary production systems. Backup integrity is verified periodically, and recovery procedures are tested to confirm that data can be restored within an acceptable timeframe following a failure event.
11. Physical Security
Our services are operated through cloud infrastructure providers who maintain physical security controls over their data centre facilities. These controls typically include restricted physical access, environmental monitoring, and redundant power and connectivity. We do not operate our own data centre facilities.
12. Personnel and Internal Controls
Personnel with access to production systems or sensitive data are subject to confidentiality obligations. Access is provisioned based on role and revoked upon change of responsibilities or departure. Internal security awareness is maintained through guidance on secure practices relevant to each role.
13. Responsible Disclosure
We welcome reports of potential security vulnerabilities from security researchers and members of the public. If you believe you have identified a security issue affecting our platform, please contact us at contact@pulevou.com with a description of the issue and steps to reproduce it. We ask that you refrain from publicly disclosing the issue until we have had a reasonable opportunity to investigate and respond.
We will acknowledge receipt of your report and keep you informed of our progress. We do not pursue legal action against individuals who report vulnerabilities in good faith and in accordance with this disclosure process.
14. Policy Review and Updates
This Security Policy is reviewed periodically and updated to reflect changes in our practices, technology, or applicable requirements. Material changes will be indicated by a revised effective date at the top of this document. Continued use of our services following such changes constitutes acknowledgement of the updated policy.
15. Contact
Questions or concerns regarding this Security Policy may be directed to:
Pulevou
Cavan Enterprise Centre, Unit 1, Killygarry, Cavan, H12 VW66, Ireland
Email: contact@pulevou.com
Phone: +353 86 827 5133