Public information security policy
| Document reference | SYS-PSEC-01 |
|---|---|
| Issue | 1 |
| Issue date | 7 October 2026 |
| Review date | 7 October 2027 |
Systech IT Solutions Ltd protects information entrusted to us and the systems used to deliver our services. This policy sets the principles we require for confidentiality, integrity and availability, including when we work with customer information.
Purpose and responsibility
We handle information only for a legitimate and authorised business purpose. We protect it from unauthorised access, use, disclosure, alteration, loss or disruption, in proportion to its sensitivity and the potential impact on people and services.
The Chief Technology Officer is accountable for this policy. People working for Systech must follow applicable security instructions, protect information in their care and raise suspected weaknesses or incidents promptly.
Access and information handling
Access must be approved for a defined role and purpose, limited to what is needed, and removed when no longer required. Customer access must stay within the agreed scope and permissions. We respect confidentiality, privacy, contractual duties and intellectual-property rights.
Information must be handled, stored, shared and disposed of using approved arrangements for its sensitivity. Credentials and other secrets must be protected and must not be placed in unsuitable channels or AI prompts. Customer information is not used for another customer or purpose without authority.
Secure work and service changes
Changes to systems, software and services must be authorised and assessed for relevant security, privacy and service risks before release. Important changes require appropriate review, testing and a recovery or rollback approach. People remain responsible for checking work, including material produced with AI assistance.
AI-assisted access to customer systems is read-only. AI does not write to customer systems or send AI-generated material directly to customers. Internal AI agents that write code or files may do so only in authorised development sandboxes or virtual machines. Human review and normal release approval remain required.
Suppliers and incident management
We select and review suppliers in proportion to the information and services they handle. Relevant agreements must address confidentiality, security, data protection, incident handling and service responsibilities. Supplier access to customer or Systech information must be authorised and limited to the agreed work.
We plan for service disruption and recovery, and maintain processes for reporting, assessing, containing and learning from security incidents. We communicate with affected customers through agreed service and incident channels when required.
Awareness and review
We provide security instructions and awareness appropriate to people’s responsibilities. Staff and contractors are expected to follow them and raise concerns without delay.
We review this policy at least annually and after material changes or incidents. The policy owner is the Chief Technology Officer. Questions or concerns can be raised using the contact details below.
Contact
For a concern, contact your usual Systech contact, email hello@systechitsolutions.co.uk or call +44 (0)1482 770583. Ask for the Chief Technology Officer or a Company Director. Please do not send passwords, access tokens or unnecessary sensitive information.