Security Policy
Last updated: October 2025
This Security Policy describes, in general terms, the principles, practices, and measures that ConsolTech adopts to protect the information, systems, and services it makes available to its clients and users. This document is informational in nature and does not constitute an express warranty of result or specific contractual commitment, without prejudice to the specific commitments that ConsolTech assumes in each Statement of Work or contract executed with the Client.
The terms defined in ConsolTech's general Terms and Conditions, such as "Client," "Services," "Deliverables," and "Statement of Work," shall have the same meaning in this document where applicable.
1. Scope of this Policy
This policy applies exclusively to ConsolTech's website and to the services and infrastructure that are under the direct control and operation of ConsolTech. It does not extend, unless expressly agreed otherwise, to products, systems, platforms, or deliverables that ConsolTech has developed and placed under the operation, custody, or administration of the Client or third parties designated by the Client, which shall be governed by the security practices that the Client adopts on its own and by the support plans specifically contracted.
2. Commitment to Security
At ConsolTech we consider information security an essential component of the provision of our services. We adopt a security-by-design approach, integrating protection considerations from the earliest stages of each project and maintaining an internal culture oriented toward the protection of data and the continuity of operations.
3. Reference Framework
Our security practices are inspired by frameworks and standards widely recognized by the industry, including, among others, OWASP recommendations, general data protection principles, and good practices for secure software development. The adoption of these frameworks does not imply formal certification or absolute compliance with all of their controls, but rather their use as a guiding reference for professional work.
4. Information Encryption
ConsolTech uses industry-standard encryption mechanisms to protect sensitive information, both during its transmission over public networks and, when applicable, in its storage. Specific algorithms, protocols, and configurations are selected based on the project profile, the Client's requirements, and the evolution of current technical recommendations.
5. Access Control and Authentication
We implement authentication and access control mechanisms aimed at ensuring that only authorized persons can access information and systems. These mechanisms may include, depending on the scope of the project, role and permission management, multi-factor authentication, session expiration, access logging, and secure credential policies.
6. Infrastructure
Solutions developed by ConsolTech may be hosted, depending on the case, on internationally recognized cloud infrastructure providers. The selection of the provider and the specific architecture are determined based on the technical, regulatory, and economic requirements of each project. ConsolTech does not guarantee the continuous or uninterrupted availability of services provided by third parties, which are governed by their own terms of use and service levels.
7. Third-Party Components and Vulnerabilities
Solutions developed by ConsolTech may incorporate libraries, dependencies, frameworks, services, and other components provided by third parties. The emergence of published vulnerabilities (including the identifiers commonly known as CVE) in such components does not, by itself, constitute a defect attributable to ConsolTech. The application of updates, patches, or replacements in response to vulnerabilities in third-party components shall be carried out in accordance with the support or maintenance plan specifically contracted by the Client, within the timelines and conditions established therein. In the absence of such a plan, their attention is neither automatic nor free of charge.
8. Monitoring and Detection
When so agreed with the Client, ConsolTech implements or configures activity logging, event monitoring, and alert generation mechanisms that allow for the identification of anomalous behaviors or potential security incidents. The scope, hour coverage, and response levels of these services are specifically defined in each Statement of Work, support plan, or maintenance contract.
9. Backups and Continuity
ConsolTech recommends and, when so agreed, configures information backup mechanisms aimed at facilitating recovery from incidents. The frequency, retention, location, and restoration procedures of backups are defined based on the project profile. Periodic verification of backup integrity and execution of restoration tests is the operational responsibility of the Client, unless ConsolTech has expressly assumed such task through a specific support contract.
10. Secure Development
In the development cycle of solutions we apply practices aimed at reducing exposure to common vulnerabilities, including input validation, secure handling of credentials, and the incorporation of technical reviews throughout the process. These practices constitute a reasonable and professional effort, without it being possible to interpret this as a guarantee of total absence of defects or vulnerabilities in the software.
The security measures incorporated in each deliverable are those that ConsolTech considers adequate and current at the time of its delivery and acceptance. The subsequent evolution of the threat environment, the emergence of new vulnerabilities, changes in technical recommendations, or the obsolescence of algorithms and components may require updates, adjustments, or evolutions of the system, which shall be provided only through a maintenance or support contract specifically contracted by the Client.
11. Incident Management
In the event a security incident is identified that directly affects the services provided by ConsolTech, we shall adopt the reasonable measures within our reach to contain the incident, restore operations, and inform the Client in accordance with the timelines and mechanisms defined in the corresponding contract or, failing that, in what is reasonable according to the circumstances and applicable regulations.
12. Shared Responsibility
Effective security of any system requires the active collaboration of all parties involved. ConsolTech protects the components under its direct control, while the Client is responsible, among other aspects, for:
- The custody and confidentiality of credentials, passwords, tokens, and other authentication mechanisms assigned to them.
- The internal management of access to the systems and the timely deactivation of user accounts that no longer require access.
- The physical and logical security of devices, networks, and environments from which the solutions are accessed.
- The proper use of the systems by their personnel and internal training in good security practices.
- The timely updating of any infrastructure, system, or service operated directly by the Client or by third parties under their engagement.
- The protection, storage, and processing of data that the Client decides to upload, generate, store, or retain in systems operated by themselves or by third parties, including the information of their own clients and end users.
- The adoption of their own business continuity plans according to their needs and regulatory obligations.
ConsolTech shall not be liable for security incidents originating from the breach of the foregoing responsibilities by the Client or by third parties under their responsibility.
13. Unauthorized Security Testing
It is expressly prohibited to perform, on the sites, systems, platforms, infrastructures, or services operated by ConsolTech, any type of security testing, vulnerability scanning, penetration testing, brute-force attack, reverse engineering, or any other activity aimed at identifying, exploiting, or demonstrating weaknesses, without prior, express, written authorization from ConsolTech delimiting the scope, timelines, and conditions of such activity. The performance of such tests without authorization may be considered an unlawful act and shall give rise to the exercise of the corresponding legal and technical actions, including immediate blocking and reporting to the competent authorities.
14. External Audits
ConsolTech reserves the right to accept, reject, condition, schedule, or limit the scope of any security audit requested by a Client or carried out on their behalf by third parties. The performance of external audits on ConsolTech's infrastructure, systems, or processes shall require a prior written agreement defining its scope, methodology, execution window, confidentiality obligations, and, where applicable, the associated costs, which may be transferred to the requesting Client.
15. Responsible Vulnerability Disclosure
If you identify a security vulnerability in any of the systems or services operated by ConsolTech, we appreciate that you report it confidentially to the email info@consoltechsv.com, refraining from disclosing it publicly, exploiting it, or using it to access third-party information while it is being analyzed and, where applicable, remediated. ConsolTech shall evaluate each report in accordance with its internal processes.
This reporting channel is exclusively collaborative in nature and does not constitute a bug bounty program, nor does it generate, in any case, the right to compensation, payment, recognition, public mention, or any other benefit in favor of the reporter.
16. Service Levels
Any specific commitment regarding service levels, such as availability percentages, response times, maintenance windows, backup frequency, or support hour coverage, shall be established solely and exclusively in the Statement of Work, support plan, or contract executed with the Client. This policy, due to its general and informational nature, does not establish or constitute, by itself, any commitment to service levels with respect to clients, users, or third parties.
17. Limitations
ConsolTech adopts reasonable technical and organizational measures, proportionate to the risks identified; however, no information system, encryption mechanism, access control, or security measure can be considered absolutely infallible. The threat environment evolves constantly, and there are factors beyond ConsolTech's reasonable control, including sophisticated attacks, third-party software vulnerabilities, force majeure events, or actions of the users themselves, that may compromise information security despite the professional diligence applied. Consequently, ConsolTech does not warrant, expressly or implicitly, the absolute inviolability of the systems or of the information processed.
All liability of ConsolTech arising from or related to this Security Policy shall be subject, in any case, to the limitations, exclusions, and liability caps established in ConsolTech's general Terms and Conditions and in the specific contract executed with the Client, which shall prevail for all purposes.
18. Regulatory Compliance
ConsolTech orients its practices in accordance with the general principles of applicable regulations on personal data protection and information security. Specific adaptation to particular sectoral or territorial regulatory frameworks, as well as any formal certification process, shall be subject to evaluation and, where applicable, to independent professional services expressly contracted with the Client.
19. Update of Measures
ConsolTech periodically reviews its practices and reserves the right to modify, update, replace, or discontinue the security measures described in this policy, without prior notice, in order to adapt them to technological evolution, sector recommendations, and the risk profile of the services provided. Substantial changes shall be reflected on this same page, indicating the date of the last update. Modifications shall apply prospectively; services and deliverables provided previously shall be understood to be protected by the measures in force at the time of their provision or delivery, without prejudice to the maintenance plans that the Client has contracted.
20. Contact
For any inquiry, clarification, or report related to this Security Policy, you may contact us through the email info@consoltechsv.com.