Security Policy
Last updated: 26 August 2026
This Security Policy outlines the measures Greenfield takes to protect your data and ensure the confidentiality, integrity, and availability of the platform.
1. Data Encryption
- In transit: All data is encrypted using TLS 1.2 or higher.
- At rest: Stored data is encrypted using industry-standard encryption protocols.
- Backups: Encrypted backups are maintained with controlled access.
2. Access Control
Access to the platform and its data is controlled through:
- Role-Based Access Control (RBAC) — Users are assigned roles that determine their access level.
- Row-Level Security (RLS) — Data visibility is enforced at the database level, ensuring users only see records they are permitted to access.
- Authentication — Secure authentication with session management and token-based verification.
- Principle of least privilege — Users are granted the minimum access necessary for their role.
3. Audit and Monitoring
All create, update, and delete actions are logged in an immutable audit trail. Audit logs include:
- User identity (email, name, role)
- Action type (create, update, delete)
- Entity type and record ID
- Before and after snapshots of changed fields
- Timestamp
Audit logs are retained for compliance purposes and are accessible to admins.
4. Infrastructure Security
The platform is hosted on secure cloud infrastructure with:
- Network firewalls and intrusion detection systems.
- Regular security patching and updates.
- DDoS protection and traffic monitoring.
- Secure API endpoints with rate limiting.
5. Data Privacy
Personal data is processed in accordance with UK GDPR. See our Privacy Policy and Data Processing Agreement for details.
6. Incident Response
In the event of a security incident:
- Our incident response team is activated immediately.
- Affected customers are notified within 72 hours of breach confirmation.
- Root cause analysis is conducted and corrective measures are implemented.
- Post-incident reviews ensure continuous improvement.
7. Employee Security
- Background checks for personnel with access to customer data.
- Security awareness training for all team members.
- Confidentiality agreements and acceptable use policies.
- Access revoked promptly upon role change or departure.
8. Vulnerability Management
We conduct regular vulnerability assessments and penetration testing. Reported vulnerabilities are triaged and remediated based on severity. If you believe you have identified a vulnerability, please contact us responsibly.
9. Business Continuity
We maintain business continuity and disaster recovery plans, including:
- Regular data backups with encryption.
- Geographic redundancy for critical services.
- Recovery time objectives (RTO) and recovery point objectives (RPO) defined per service tier.