Security Policy

Security Policy

Information Security Policy

Venture CO Group · Last updated: July 2026 · Annual review cycle

Last updated: July 2026

1. Purpose and Commitment

Venture CO Group is committed to protecting the confidentiality, integrity, and availability of the information entrusted to us by our clients, partners, and employees. This Information Security Policy sets out the principles and controls we apply across our organization, and reflects our commitment to operating securely in a distributed, cloud-first working environment.

This document is the public summary of our internal information security framework. Detailed internal standards, procedures, and technical baselines support each area described below.

2. Scope

This policy applies to:

  • All employees, contractors, and third parties who access Venture CO Group information or systems;
  • All information assets we own or process, whether digital or physical;
  • All systems, devices, cloud services, and networks used to conduct our business, across all countries in which we operate (Hungary/EU, the United Kingdom, the United States, Turkey, and Uzbekistan).

3. Governance and Responsibilities

  • Executive management holds ultimate accountability for information security and approves this policy.
  • A designated security owner is responsible for maintaining the security program, coordinating risk assessments, and overseeing incident response.
  • Every member of staff is responsible for applying this policy in their daily work and for reporting suspected security issues without delay.
  • Security requirements are integrated into business decisions, projects, and vendor selection from the outset (“security by design and by default”).

4. Guiding Principles (ISO 27001 Alignment)

Our security program is aligned with the principles of ISO/IEC 27001, the international standard for information security management. In particular, we apply:

  • Risk-based management — periodic risk assessments drive the selection and prioritization of controls.
  • Least privilege — access to information is limited to what is necessary for a person’s role.
  • Defense in depth — multiple, overlapping layers of technical and organizational controls.
  • Continuous improvement — controls are reviewed, tested, and refined on an ongoing basis.

5. Access Control and Authentication

  • Access to systems and data is granted on a role-based, need-to-know basis and reviewed periodically.
  • Multi-factor authentication (MFA) is required for administrative access and for remote access to business-critical systems and cloud services.
  • Strong password requirements and, where available, phishing-resistant authentication methods are enforced.
  • Access rights are revoked promptly when a person leaves the organization or changes role.

6. Encryption

  • In transit: All connections to our website and business systems are protected with TLS encryption (HTTPS). Internal and third-party integrations use encrypted channels.
  • At rest: Business data stored in our cloud services and on company-managed devices is encrypted at rest using industry-standard algorithms.
  • Cryptographic keys and credentials are managed securely and are never embedded in source code or shared through insecure channels.

7. Secure Development and Website Operations

  • Our website and digital services are developed and maintained following secure development practices, including code review, dependency management, and the separation of production and non-production environments.
  • The WordPress platform underlying our website, together with its themes and plugins, is kept current and limited to vetted, actively maintained components.
  • Administrative interfaces are protected with strong authentication and access restrictions.

8. Patch and Vulnerability Management

  • Operating systems, applications, and website components are updated on a defined schedule, with critical security patches prioritized for rapid deployment.
  • We monitor vendor advisories and threat intelligence for vulnerabilities affecting the technologies we use.
  • Periodic vulnerability assessments are performed on internet-facing assets, and identified issues are remediated according to their severity.

9. Backups and Disaster Recovery

  • Business-critical data and website content are backed up regularly, with backups stored securely and separately from production systems.
  • Backup restoration is tested periodically to verify recoverability.
  • Disaster recovery and business continuity arrangements define how we restore key services following a significant disruption, with recovery priorities based on business impact.

10. Incident Response and Breach Notification

  • We maintain a documented incident response process covering detection, containment, eradication, recovery, and post-incident review.
  • All employees are required to report suspected security incidents immediately.
  • In the event of a personal data breach, we act in accordance with the GDPR: where a breach is likely to result in a risk to individuals’ rights and freedoms, we notify the competent supervisory authority (in Hungary, the NAIH) without undue delay and, where feasible, within 72 hours of becoming aware of it, and we inform affected individuals without undue delay where the breach is likely to result in a high risk to them.
  • Lessons learned from incidents are fed back into our controls and training.

11. Vendor and Third-Party Risk Management

  • Before engaging service providers who handle our data, we assess their security posture and data protection practices.
  • Processors of personal data are bound by data processing agreements consistent with Article 28 GDPR.
  • Vendor access to our systems is limited, monitored, and revoked when no longer required.
  • Significant vendors are reviewed periodically for continued compliance with our requirements.

12. Employee Awareness and Training

  • All employees receive information security and data protection awareness training when they join us and refresher training on a regular basis.
  • Training covers current threats such as phishing, social engineering, and safe handling of confidential information.
  • Staff working across our international locations receive guidance relevant to their local regulatory context.

13. Physical and Environmental Security

  • Access to our office premises is controlled and limited to authorized persons.
  • Company devices are encrypted, protected with screen locks, and can be remotely wiped if lost or stolen.
  • We apply a clear-desk and clear-screen approach for confidential information, and paper records containing sensitive data are stored securely and disposed of by shredding.
  • Production infrastructure is hosted with reputable providers that maintain certified physical security controls in their data centers.

14. Acceptable Use

All personnel using Venture CO Group systems must:

  • Use company systems and data only for legitimate business purposes;
  • Keep credentials confidential and never share accounts;
  • Not install unauthorized software or connect unapproved devices to company systems;
  • Not attempt to bypass security controls;
  • Handle confidential and personal data in line with our Privacy Policy and internal procedures.

Violations of this policy may result in disciplinary action and, where applicable, legal consequences.

15. Responsible Disclosure

We value the contribution of security researchers and members of the public who help keep our services safe. If you believe you have found a security vulnerability in our website or systems:

  • Report it to us at contact@ventureco.group with sufficient detail to reproduce the issue;
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it, and do not access, modify, or delete data belonging to others;
  • Allow us a reasonable time to investigate and remediate before any public disclosure.

We will acknowledge your report, keep you informed of progress where possible, and will not pursue legal action against good-faith research conducted in line with these principles.

16. Review and Maintenance

This policy is reviewed at least annually, and additionally following significant changes to our business, technology, threat landscape, or legal obligations. The “Last updated” date above reflects the most recent revision.

17. Contact

Questions about this policy may be directed to:

Venture CO Group 1036 Budapest, Pacsirtamező utca 65. VI. em. 4., Hungary Email: contact@ventureco.group Contact page: https://ventureco.group/enquiry/