At we.Shi, protecting your data and maintaining your trust is our highest priority. Our security program is built on industry best practices and is designed to safeguard the confidentiality, integrity, and availability of your information.
Comprehensive Security Policies:
We maintain a robust set of security policies covering access control, asset management, incident response, risk management, and more. These policies are regularly reviewed and updated to reflect evolving threats and regulatory requirements.
Employee Awareness & Training:
All we.Shi personnel and contractors complete security awareness training at the time of hire and annually thereafter. Ongoing security communications ensure our team stays informed about the latest security practices and threats.
Access Controls:
Access to systems and data is strictly limited to authorized personnel based on business needs. We enforce strong password policies, multi-factor authentication, and regular access reviews.
Data Protection:
We use encryption and other technical safeguards to protect your data both in transit and at rest. Our data management practices ensure information is classified and handled according to its sensitivity.
Incident Response:
We have a documented incident response plan to quickly identify, contain, and remediate security incidents. Our team is trained to respond promptly to any potential threats.
Vendor & Third-Party Security:
We assess the security practices of our vendors and partners to ensure they meet our standards for data protection.
Continuous Improvement:
Our risk management process includes regular assessments and updates to our security controls, ensuring we adapt to new risks and technologies.
Compliance
we.Shi aligns its security program with recognized industry standards and frameworks. We are committed to maintaining compliance with applicable laws and regulations.
If you believe you have discovered a security vulnerability or incident related to we.Shi, please contact our security team at: soc2@we-shi.com
We appreciate responsible disclosure and will respond promptly to all legitimate reports.