Security
RAEFORM recognizes that clients may entrust us with business information, systems access, files, and personal information.
Overview
We use reasonable security practices designed to protect the confidentiality, integrity, and availability of information within our control.
Philippine privacy rules require covered organizations processing personal data to maintain reasonable and appropriate safeguards based on the nature and risks of their processing.
Our Security Approach
Depending on the relevant system and service, safeguards may include:
- Controlled authentication
- Role-based or need-based access
- Limited administrative permissions
- Secure transmission technologies
- Hosted infrastructure provided by established service providers
- Credential management practices
- Logging and monitoring
- Backup and recovery procedures
- Security updates and maintenance
- Data minimization
- Confidentiality obligations
- Incident-response procedures
- Appropriate third-party service management
Specific controls may vary depending on the system, client arrangement, and nature of the information involved.
Least Necessary Access
Where practicable, RAEFORM seeks to limit access to systems and information to individuals who reasonably require access for authorized work.
Client Credentials
Where clients provide system access, RAEFORM expects credentials and permissions to be limited to what is reasonably necessary for the engagement.
Clients remain responsible for managing their own systems, account ownership, and administrator access unless otherwise agreed.
Third-Party Providers
RAEFORM relies on third-party infrastructure and software providers for certain services.
Those providers maintain their own security practices and responsibilities.
No Absolute Security Guarantee
No technology, network, storage system, or internet transmission can be guaranteed completely secure.
RAEFORM does not represent that its systems are immune from every security incident.
Reporting Security Concerns
Potential vulnerabilities or security concerns involving RAEFORM should be reported responsibly to:
hello@byraeform.com
Please do not publicly disclose a potential vulnerability before RAEFORM has had a reasonable opportunity to investigate it.