Effective August 1, 2026
1. Scope and principles
This Policy describes Emasmas's common security framework for its websites and cloud-based digital products. Controls vary by architecture, plan and risk; a product order may add commitments. We manage confidentiality, integrity, availability, privacy by design and least privilege according to risk. No measure guarantees absolute security.
2. Organization and controls
We assign security duties, limit access by role, require confidentiality, review relevant permissions and remove unnecessary access. Training reflects staff access and responsibilities.
Depending on service and risk, controls include authentication and role-based access; current transport encryption and appropriate at-rest encryption where supported; logical separation; security logging and monitoring; protected backups and recovery testing; vulnerability, patch and change management; continuity and defenses against malicious code, abuse and unauthorized access.
3. Providers, development and incidents
We assess providers by risk and require contractual security, privacy and confidentiality. Development practices proportionately cover change review, secrets, dependencies and environment separation.
Incident procedures address detection, containment, investigation, recovery and lessons learned. Notifications occur without undue delay or within legally/contractually required periods, including under Chilean Law 19,628 as amended by Law 21,719, GDPR and applicable U.S. federal or state law.
4. Customer duties and reporting
Customers must protect credentials and devices, use stronger authentication where available, review users and permissions, secure integrations, keep external backups if continuity requires and promptly report suspicious activity.
Report vulnerabilities to contacto@emasmas.cl with reproduction steps, without accessing, changing, downloading or disclosing others' data. Do not conduct denial-of-service, social-engineering or destructive tests. We will investigate in good faith and coordinate remediation and responsible disclosure.
We review this framework as risks, products or laws change and withhold details that would facilitate attacks. Additional information may be available under confidentiality.