Security
This page describes how this site is protected. It is written in principles rather than specifics, because publishing the details of a defence is a way of weakening it.
In transit
Everything between your browser and this site travels encrypted. There is no unencrypted version of the site to reach by accident.
At rest
Anything submitted through the site is stored encrypted, kept separate from other organisations’ information, and reachable only by people who need it to do their work.
Keeping it current
The software this site is built on is checked regularly for known weaknesses, and updates are applied on a schedule rather than when something goes wrong. Backups are taken daily and their success is verified, because a backup nobody checks is not a backup.
Access
Administrative access requires more than a password, and is limited to the smallest number of people who need it.
Our standard
This site is built to the Kwata Security Standard and aligned with PIPEDA and Alberta PIPA. We do not hold a SOC 2 attestation or an ISO 27001 certification, and we do not describe ourselves as certified or compliant. Where we say “built to” and “aligned with”, we mean exactly that.
Telling us about a problem
If you believe you have found a security problem with this site, please tell us before telling anyone else, and we will work with you. We will not pursue anyone who reports a genuine issue in good faith.
Questions about this page, or a request about your own information, can go to office@whitehorncommunity.com.