InventoryPro

Information Security Policy

How CISS Ltd. protects client data and manages information security.

Last updated: September 2026

Purpose and Scope

This policy defines how CISS Ltd. ("CISS") protects the confidentiality, integrity, and availability of the information we hold on behalf of our clients and the systems we operate. It applies to all CISS employees, contractors, and third parties who access CISS systems, networks, or client data, and to all systems that process, store, or transmit client information.

The policy covers the Inventory Pro platform and the infrastructure that supports it, including cloud-hosted client instances, the mobile application, the REST API, and the supporting development and deployment tooling.

Governance and Frameworks

CISS maintains alignment with the NIST Cybersecurity Framework (CSF) 2.0 as our primary security framework, and we align our controls with ISO 27001. We however are not certified. Our cloud infrastructure provider (Microsoft Azure) holds ISO 27001, SOC 1/2/3, HIPAA, FedRAMP, and PCI DSS certifications.

Security responsibilities are assigned within the team, and this policy is reviewed and updated after significant changes to the platform, infrastructure, or regulatory landscape.

Access Control

CISS enforces the principle of least privilege. Access to systems and client data is granted only where required for a role and is reviewed periodically. Role-based access control with granular permissions governs what each user can view and modify within Inventory Pro.

  • Administrative access to production systems requires strong authentication and is not exposed to the public internet.
  • Remote access is tightly restricted, limited to authorized personnel, and never exposed to the public internet.
  • Access is revoked promptly on employee departure or role change, and shared credentials are rotated.
  • Client data is isolated per organization with dedicated database instances.

Authentication and Password Security

Passwords are stored using strong, salted, computationally intensive hashing algorithms designed to protect credentials even if a database is compromised. Inventory Pro supports configurable password policies including minimum length, complexity, maximum age, history enforcement, and account lockout after repeated failed attempts.

Single sign-on is supported through various identity providers and systems ( CAC/Smart Card, Active Directory, etc ), allowing organizations to centralize identity governance.

Encryption

All data transmitted between clients and Inventory Pro is encrypted in transit using TLS 1.2 or higher, with HSTS enforced across all endpoints. Backups are encrypted using AES-256 and distributed across multiple geographic locations. Administrative and database networks are isolated from the public internet.

Secure Development

Security is considered throughout the software development lifecycle. Our secure development standard requires parameterized queries to prevent SQL injection, input validation and output encoding to prevent cross-site scripting, and consistent error handling. Code changes are reviewed before release, and security scanning is applied to the codebase and dependencies.

Monitoring and Incident Response

Production systems are monitored continuously with automated alerting for service availability and security events. Audit logs record user activity, authentication events, and configuration changes.

CISS maintains an incident response plan covering detection, containment, eradication, recovery, and post-incident review. Suspected security events are reported immediately to the security team, and clients are notified of incidents affecting their data in accordance with applicable law and contractual obligations.

Business Continuity and Recovery

Cloud-hosted instances operate under a 99% monthly uptime commitment. Production databases are backed up across multiple tiers with geographic redundancy, including daily full backups, encrypted off-platform storage, and on-premises copies. Restore procedures are documented for each backup tier, and routine client restores provide ongoing validation that backups are recoverable.

Third Parties and Vendors

Sub-processors involved in service delivery are limited to CISS Ltd., Microsoft Azure, and our off-platform backup provider. Vendors are selected from established providers, assessed for security posture, and reviewed at renewal. CISS does not sell, rent, or share client data with third parties.

Reporting a Vulnerability

We welcome responsible disclosure of security vulnerabilities. If you believe you have found a security issue in Inventory Pro or the CISS website, please report it to us directly at support@cissltd.com. Please include a description of the issue, the affected component and version, and steps to reproduce. We will acknowledge receipt and work to address confirmed issues promptly.

Questions about our security practices? Contact us at support@cissltd.com.