1. Security approach
Sanmarris uses a risk-based approach to security across our technology and business operations. Controls are designed to protect confidentiality, integrity and availability while supporting practical business operations.
2. Security practices
Depending on the system and service, practices may include access controls and least-privilege principles, authentication controls, secure software-development practices, encryption in transit, logging and monitoring, backups and recovery processes, vulnerability management, change management and supplier risk review.
Specific customer security commitments are defined in applicable contracts and technical documentation. This page intentionally does not claim certifications or attestations that have not been expressly confirmed by Sanmarris.
3. Data protection
We seek to minimise unnecessary collection of personal information and use safeguards appropriate to the nature of the information and service. Customer data handling may vary by product, deployment and contractual requirements.
4. Incident management
We maintain processes intended to identify, assess and respond to security incidents. Where an incident triggers legal or contractual notification obligations, Sanmarris will follow the applicable requirements.
5. Report a security concern
If you believe you have identified a security vulnerability or incident affecting Sanmarris, contact security@sanmarris.com. Please provide enough information for us to understand and reproduce the issue, but do not access, alter or exfiltrate data that is not yours.