Information Security Statement
Our Commitment
At Contego AI, security is fundamental to everything we do.
As a company developing intelligent, non-invasive threat detection technologies for public safety and critical environments, we recognise that the protection of information, systems, and customer trust is essential to everything we do.
We are committed to implementing appropriate technical, organisational, and administrative safeguards designed to protect the confidentiality, integrity, and availability of the information entrusted to us.
Our security programme is continuously reviewed and developed to support the evolving needs of our customers, partners, employees, and stakeholders.
Security Principles
Our approach to information security is guided by the following principles:
- Security by Design
- Privacy by Design
- Least Privilege Access
- Defence in Depth
- Secure Development Practices
- Continuous Risk Management
- Transparency and Accountability
- Continuous Improvement
These principles underpin the design, development, deployment, and operation of our products, services, and internal business systems.
Information Security Governance
Information security is supported throughout the organisation by executive leadership and is considered an integral component of business operations.
We maintain policies, procedures, and internal processes that are designed to:
- identify and manage security risks
- protect confidential information
- support regulatory compliance
- safeguard intellectual property
- respond effectively to security incidents
- promote a culture of security awareness
Security Controls
Contego AI implements security measures appropriate to the nature of our business and the information we process.
These measures may include:
Identity and Access Management
- Role-based access controls
- Principle of least privilege
- Multi-factor authentication
- Strong authentication requirements
- Periodic access reviews
Infrastructure Security
- Secure cloud-hosted environments
- Network segmentation where appropriate
- Firewall protection
- Encrypted communications
- Continuous system monitoring
Data Protection
- Encryption in transit using industry-standard protocols
- Encryption at rest where appropriate
- Secure backup processes
- Controlled access to sensitive information
- Data minimisation practices
Endpoint Security
- Managed endpoint protection
- Operating system updates
- Patch management
- Malware protection
- Device security controls
Secure Software Development
Security considerations are incorporated throughout the software development lifecycle.
Where appropriate, this includes:
- secure design reviews
- code review
- dependency management
- vulnerability identification and remediation
- security testing before release
- ongoing maintenance
Vulnerability Management
Contego AI is committed to identifying and addressing security vulnerabilities promptly.
Our vulnerability management activities may include:
- regular security reviews
- software updates and patch management
- monitoring of published vulnerabilities
- responsible vulnerability disclosure
- risk-based remediation
Security researchers are encouraged to report suspected vulnerabilities in accordance with our Responsible Disclosure Policy.
Incident Management
Contego AI maintains procedures designed to identify, investigate, contain, and respond to security incidents.
Where appropriate, incidents are assessed, documented, investigated, and remediated, with lessons learned incorporated into future improvements.
Where legally required, affected customers and regulatory authorities will be notified in accordance with applicable laws and contractual obligations.
Privacy and Data Protection
Privacy forms a core part of our security philosophy.
We seek to collect only the personal information necessary for legitimate business purposes and implement appropriate safeguards to protect that information.
Our privacy practices are described in our Privacy Policy and related documentation.
Third-Party Risk
We recognise that third-party suppliers and service providers play an important role in our operations.
Where appropriate, we seek to work with reputable providers that maintain appropriate security practices and contractual commitments relating to information security and data protection.
Business Continuity
Contego AI is committed to maintaining resilient business operations.
We implement measures designed to support service continuity, data protection, backup, and recovery, while continually reviewing risks that may affect business operations.
Security Awareness
Information security is everyone's responsibility.
Personnel with access to company information are expected to act responsibly, follow established security procedures, and protect confidential information appropriately.
Security awareness forms part of our ongoing organisational culture.
Continuous Improvement
Information security is an ongoing process.
As our products, customer base, and operational footprint continue to grow, we will continue to review, strengthen, and mature our security programme through ongoing risk assessment, process improvement, technology investment, and alignment with recognised industry best practices.
Contact Us
If you have questions regarding this Policy, please contact:
Contego AI, Inc.
Email: privacy@contego.ai
Website: www.contego.ai