How We Approach Security
Practices we build into every engagement — not a certification badge, but how we actually design and operate systems.
IT-ISS does not currently hold formal third-party certifications such as SOC 2 or ISO 27001. The principles below describe the practices we apply to our own products and client engagements today.
🔒 Encryption at Rest & In Transit
Sensitive data encrypted in the database and in transit between services, applied consistently across the products we build and operate — including SPAM Escudo and Cerberus ID.
🔐 Least-Privilege Access Control
IAM roles, VPC segmentation, and Security Group hardening scoped down to the individual role and resource, not broad standing access.
🧩 PII Minimization
No personal data retained beyond what a decision or feature strictly requires — a first-class architectural requirement in products like SPAM Escudo and Cerberus ID, not an afterthought.
🌐 GDPR/CCPA-Aware Architecture
Data handling designed around GDPR and CCPA localization and retention requirements from the start, rather than bolted on after the fact.
🧲 Patch & Vulnerability Management
Scheduled OS and database patching, and version upgrades, handled on a planned cadence as part of our managed-services work.
🧪 Backup Verification & DR Drills
Proving that backups actually restore — not just that they run — through scheduled recovery drills against real DR runbooks.