Security

Korven One Information Security Policy

Korven One is committed to protecting the confidentiality, integrity, availability, and security of customer information, financial data, systems, infrastructure, and services. This Policy establishes the security principles, controls, and responsibilities governing Korven One operations.

Last updated: Version 1.0 Draft · Effective Date: To Be Determined

1. Purpose

Korven One is committed to protecting the confidentiality, integrity, availability, and security of customer information, financial data, systems, infrastructure, and services. This Information Security Policy establishes the security principles, controls, and responsibilities governing Korven One operations.

2. Scope

This Policy applies to:

  • Employees
  • Contractors
  • Developers
  • Merchants
  • Partners
  • Service Providers
  • Infrastructure Systems
  • Applications
  • APIs
  • Databases
  • Cloud Services

3. Security Principles

Korven One follows the following principles:

  • Security First
  • Least Privilege
  • Defense in Depth
  • Zero Trust
  • Continuous Monitoring
  • Auditability
  • Compliance by Design

4. Information Classification

Information may be classified as:

Public

Information approved for public release.

Internal

Information intended for internal use.

Confidential

Sensitive business information.

Restricted

Highly sensitive information requiring enhanced protection. Examples:

  • Financial Records
  • Customer Data
  • KYC Data
  • Treasury Information
  • Security Credentials

5. Identity and Access Management

Korven One shall implement:

  • Role-Based Access Control (RBAC)
  • Multi-Factor Authentication (MFA)
  • Password Security Controls
  • Session Management
  • Access Reviews
  • Privileged Access Controls

Access shall be granted only when necessary for business purposes.

6. Authentication Standards

Korven One may require:

  • MFA
  • Device Verification
  • Session Validation
  • Strong Password Requirements

Administrative and privileged accounts must use MFA.

7. Encryption Standards

Korven One shall implement:

Encryption In Transit

TLS 1.2 or higher. Preferred standard: TLS 1.3.

Encryption At Rest

AES-256.

Sensitive Data Protection

Sensitive information must be encrypted where appropriate.

8. API Security

Korven One shall implement:

  • API Authentication
  • API Authorization
  • Rate Limiting
  • API Key Rotation
  • Webhook Security
  • Request Validation
  • Abuse Detection

API credentials must be protected.

9. Application Security

Korven One shall maintain secure software development practices. Security controls may include:

  • Code Reviews
  • Dependency Scanning
  • Vulnerability Scanning
  • Security Testing
  • Secure Deployment Practices

10. Infrastructure Security

Korven One shall maintain:

  • Network Security Controls
  • Firewall Protection
  • DDoS Protection
  • Cloud Security Controls
  • Infrastructure Monitoring
  • Secure Configuration Standards

Infrastructure shall be regularly reviewed.

11. Logging and Monitoring

Korven One shall maintain:

  • Audit Logs
  • Security Logs
  • Application Logs
  • Infrastructure Logs

Monitoring systems may be used to identify:

  • Unauthorized Access
  • Fraud
  • Security Events
  • Operational Risks

12. Financial Security Controls

Korven One shall implement:

  • Double Entry Ledger Controls
  • Transaction Audit Trails
  • Settlement Controls
  • Treasury Controls
  • Approval Workflows
  • Fraud Monitoring

All financial events must be auditable.

13. Fraud Prevention

Korven One may implement:

  • Transaction Monitoring
  • Risk Scoring
  • Behavioral Analytics
  • Device Analysis
  • Fraud Detection Systems
  • Velocity Controls

Suspicious activity may be investigated.

14. Vulnerability Management

Korven One shall maintain processes for:

  • Vulnerability Identification
  • Risk Assessment
  • Remediation
  • Verification

Critical vulnerabilities should be addressed promptly.

15. Incident Reporting

Employees, contractors, and partners must report suspected security incidents immediately. Examples include:

  • Unauthorized Access
  • Credential Exposure
  • Malware
  • Data Exposure
  • Fraud Events

16. Third-Party Risk Management

Korven One may assess third-party providers based on:

  • Security Practices
  • Compliance Standards
  • Operational Reliability
  • Risk Exposure

Third-party access shall be reviewed periodically.

17. Business Continuity

Korven One shall maintain controls designed to support:

  • Service Availability
  • Disaster Recovery
  • Data Protection
  • Operational Resilience

Business continuity procedures may be tested periodically.

18. Security Awareness

Employees and contractors may receive periodic training regarding:

  • Security Practices
  • Fraud Prevention
  • Compliance Requirements
  • Data Protection

19. Compliance

Korven One may maintain controls supporting:

  • AML Programs
  • KYC Programs
  • Data Protection Requirements
  • Financial Compliance Requirements
  • Security Audits

20. Policy Violations

Violations of this Policy may result in:

  • Access Restrictions
  • Account Suspension
  • Contract Termination
  • Legal Action

as appropriate.

21. Governance

Korven One management shall maintain oversight of:

  • Security Programs
  • Risk Management
  • Compliance Activities
  • Security Monitoring

Periodic reviews may be conducted.

22. Policy Updates

Korven One may update this Policy periodically. Updated versions will be published through Korven One Services and website.

23. Contact Information

Korven One Security Team

Email: security@korvenone.com

Email: compliance@korvenone.com

Support: support@korvenone.com

Website: https://korvenone.com

24. Language

The official version of this Security Policy is the English version. Translations may be provided in:

  • Haitian Creole
  • French
  • Spanish

In case of conflict, the English version shall prevail.

Questions about this document?

Contact our team at legal@korvenone.com. For security matters, email security@korvenone.com.