1.Purpose and scope
This policy describes the information security controls that Shefa Digital applies to the Shefy platform (the web application, its backend infrastructure, and the data processed through it) and to the personal and business data of Shefy's users. Shefa Digital is a small, owner-operated sole proprietorship, not a large enterprise; the controls described below are proportionate to the nature and size of the business and to the sensitivity of the data processed, not the security program of a large regulated financial institution.
2.Access control and least privilege
Administrative and production access to Shefy's infrastructure is restricted to the individuals who operate the business, on an as-needed basis. Within the application itself, every business's data (clients, quotes, invoices, appointments, payments) is strictly isolated from every other business's data — every request is validated server-side against the identity of the authenticated caller before any read or write is permitted, and a user can only ever access data belonging to their own company.
3.Authentication and credential handling
User accounts are protected by a password, which is never stored in plain text (it is stored using industry-standard one-way hashing). Users can enable two-factor authentication (by email or SMS) on their account for an additional layer of protection; we encourage its use, in particular for accounts with access to sensitive business data.
4.Secure communications
All traffic between users and the Shefy platform is encrypted in transit using HTTPS/TLS.
5.Secrets management
Credentials and API keys used by the platform (for example, to communicate with third-party providers) are held as environment-level configuration on the production infrastructure. They are not committed to source control and are not shared beyond what is operationally necessary.
6.Database and data access controls
The production database is not exposed publicly. Access is restricted to the platform's own backend service and, for maintenance purposes, to the individuals who operate the business.
7.Logging and monitoring
The platform maintains application-level logging to support troubleshooting and the security review of its own infrastructure.
8.Vulnerability and dependency management
Software dependencies used by the platform are reviewed and updated periodically to address known vulnerabilities.
9.Secure development and testing
Changes to the platform are reviewed before being deployed to production, and are exercised against an automated test suite covering core account, billing, and data-isolation behaviour before release.
10.Backup and recovery
Application data is backed up on a regular basis and retained for a limited period, to support recovery in the event of data loss.
11.Incident response
Shefa Digital investigates any suspected security incident affecting the Shefy platform without undue delay, takes reasonable steps to contain and remediate it, and will notify affected users and/or the relevant authorities where required by applicable law.
12.Third-party service providers
Shefy relies on a small number of established third-party providers for hosting, storage, communications, and AI-assisted processing. These providers are selected with their own security practices in mind, and any access granted to them is limited to what is necessary for them to provide their service. See our Privacy Policy for the categories of providers used.
13.Data minimisation
Shefa Digital collects and retains only the data necessary to provide the Shefy service, as described in our Privacy Policy.
14.Personnel and contractor access
Shefa Digital is a sole proprietorship with no employees. Access to production systems is limited to its owner/operator, and to any contractor engaged on a specific, limited basis, only for as long as required for that engagement, and revoked promptly once no longer needed.
15.Payment card data
Shefa Digital does not store, process, or transmit cardholder data directly. Payment card processing is outsourced to PCI DSS-compliant payment service providers. Any applicable PCI DSS responsibilities are managed according to the integration model and the requirements of the acquiring/payment provider.
16.Certifications
Shefa Digital does not currently hold formal third-party security certifications (such as ISO 27001, SOC 2, or PCI DSS). The controls described in this policy are self-implemented and proportionate to the business, as stated in section 1.
17.Review and updates
This policy is reviewed periodically and updated as the business, its infrastructure, or its risk profile evolves.
18.Contact
Questions about this policy can be sent to contact@shefyone.com.