The top-level information-security policy that governs how Ekosistem App is built, run and maintained.
This policy establishes the security objectives and minimum controls for the Ekosistem App platform — the web application, the API, the persistent stores, the third-party services and the human processes around them. It applies to all engineering work performed by Plademy Oy and any service provider acting on its behalf.
Ekosistem App follows defense-in-depth: every external request crosses authentication, authorization, validation, rate-limit, sanitization and audit boundaries before it can change state. The minimum required controls are:
Day-to-day operations are run by Plademy Oy's engineering team. The following practices are mandatory:
Plademy Oy is the operator of the platform. The following roles are accountable:
This policy is reviewed at least annually, after every material change to the platform or stack, and following any security incident. Comments or concerns can be sent to developer@plademy.com.