1. Security principles
Hlulo is designed around controlled access, operational accountability and auditable workflows. Security practices evolve with the platform, deployment architecture, threat environment and customer requirements.
2. Access control
Hlulo supports role-based access patterns so that users can be given capabilities appropriate to their responsibilities. Customer configuration, administrator practices and identity controls also contribute to the security of a deployment.
3. Operational controls
The platform is designed to support controlled workflows, approvals, accountability and auditability across operational processes. Individual security and governance capabilities may depend on the modules and deployment configuration in use.
4. Infrastructure and data protection
We use reasonable technical and organisational measures appropriate to the services being operated. These may include controls around authentication, access, infrastructure configuration, transport security, logging, backups, software updates and operational monitoring.
5. Security responsibilities
Security is shared. Customers and authorised users are responsible for protecting account credentials, managing authorised access, following their organisation's security policies and reporting suspected compromise promptly.
6. Responsible reporting
If you believe you have identified a security issue affecting Hlulo, please contact us through the Hlulo Contact page and clearly mark the enquiry as a security report. Do not publicly disclose sensitive technical details or access data that you are not authorised to view.
7. No absolute-security claim
No internet-connected service can guarantee absolute security. This page describes our general security approach and is not a warranty, certification or substitute for security commitments contained in a signed customer agreement.
