How CISS Ltd. protects client data and manages information security.
Last updated: September 2026
This policy defines how CISS Ltd. ("CISS") protects the confidentiality, integrity, and availability of the information we hold on behalf of our clients and the systems we operate. It applies to all CISS employees, contractors, and third parties who access CISS systems, networks, or client data, and to all systems that process, store, or transmit client information.
The policy covers the Inventory Pro platform and the infrastructure that supports it, including cloud-hosted client instances, the mobile application, the REST API, and the supporting development and deployment tooling.
CISS maintains alignment with the NIST Cybersecurity Framework (CSF) 2.0 as our primary security framework, and we align our controls with ISO 27001. We however are not certified. Our cloud infrastructure provider (Microsoft Azure) holds ISO 27001, SOC 1/2/3, HIPAA, FedRAMP, and PCI DSS certifications.
Security responsibilities are assigned within the team, and this policy is reviewed and updated after significant changes to the platform, infrastructure, or regulatory landscape.
CISS enforces the principle of least privilege. Access to systems and client data is granted only where required for a role and is reviewed periodically. Role-based access control with granular permissions governs what each user can view and modify within Inventory Pro.
Passwords are stored using strong, salted, computationally intensive hashing algorithms designed to protect credentials even if a database is compromised. Inventory Pro supports configurable password policies including minimum length, complexity, maximum age, history enforcement, and account lockout after repeated failed attempts.
Single sign-on is supported through various identity providers and systems ( CAC/Smart Card, Active Directory, etc ), allowing organizations to centralize identity governance.
All data transmitted between clients and Inventory Pro is encrypted in transit using TLS 1.2 or higher, with HSTS enforced across all endpoints. Backups are encrypted using AES-256 and distributed across multiple geographic locations. Administrative and database networks are isolated from the public internet.
Security is considered throughout the software development lifecycle. Our secure development standard requires parameterized queries to prevent SQL injection, input validation and output encoding to prevent cross-site scripting, and consistent error handling. Code changes are reviewed before release, and security scanning is applied to the codebase and dependencies.
Production systems are monitored continuously with automated alerting for service availability and security events. Audit logs record user activity, authentication events, and configuration changes.
CISS maintains an incident response plan covering detection, containment, eradication, recovery, and post-incident review. Suspected security events are reported immediately to the security team, and clients are notified of incidents affecting their data in accordance with applicable law and contractual obligations.
Cloud-hosted instances operate under a 99% monthly uptime commitment. Production databases are backed up across multiple tiers with geographic redundancy, including daily full backups, encrypted off-platform storage, and on-premises copies. Restore procedures are documented for each backup tier, and routine client restores provide ongoing validation that backups are recoverable.
Sub-processors involved in service delivery are limited to CISS Ltd., Microsoft Azure, and our off-platform backup provider. Vendors are selected from established providers, assessed for security posture, and reviewed at renewal. CISS does not sell, rent, or share client data with third parties.
We welcome responsible disclosure of security vulnerabilities. If you believe you have found a security issue in Inventory Pro or the CISS website, please report it to us directly at support@cissltd.com. Please include a description of the issue, the affected component and version, and steps to reproduce. We will acknowledge receipt and work to address confirmed issues promptly.
Questions about our security practices? Contact us at support@cissltd.com.