Information Security Policy

Updated: June 2026

Our Commitment

ECAT is committed to protecting the confidentiality, integrity, and availability of information entrusted to us by our clients, partners, and stakeholders. Information security is fundamental to our business as a provider of electronic process validation software and compliance services.

This policy summarises our approach to information security. Our full Information Security Management System (ISMS) is certified to ISO/IEC 27001:2022, independently audited by NSAI (National Standards Authority of Ireland).

Certification

 

Standard

ISO/IEC 27001:2022

Certification Body

NSAI (National Standards Authority of Ireland)

NSAI File No.

27001.81

Scope

The provision of electronic process validation software and supporting services

Certificate Expiry

29 January 2029

Surveillance Audits

Annual — conducted by NSAI

 

How We Protect Your Information

Cloud-First Architecture

ECAT operates a cloud-first infrastructure on an enterprise cloud platform. Our production systems are hosted in ISO 27001 and SOC 2 certified data centres located in Ireland and the United Kingdom.

Access Control

Access to ECAT systems is governed by the principle of least privilege. All user access requires multi-factor authentication (MFA). Risk-based access policies enforce additional controls based on user identity, device compliance, and location. Access rights are reviewed regularly and revoked promptly when no longer required.

Encryption

All data is encrypted at rest and in transit. Corporate devices use full-disk encryption. Cloud data is protected by platform-level encryption. Communications between ECAT systems use TLS 1.2 or higher.

Endpoint Security

All ECAT corporate devices are enrolled in our mobile device management platform with compliance policies enforced. Devices are monitored for security threats, patched regularly, and protected by enterprise-grade endpoint detection and response (EDR) capabilities.

Vulnerability Management

ECAT maintains a continuous vulnerability management programme. Security configurations are monitored weekly, and identified vulnerabilities are assessed, prioritised, and remediated within defined service levels. We conduct regular security assessments and vulnerability reviews, and engage independent security firms as part of our security assurance programme.

Personnel Security

All ECAT employees and contractors are subject to appropriate background checks and are required to sign confidentiality agreements. Information security awareness training is provided to all staff, covering topics including phishing, data protection, and secure working practices.

Incident Management

ECAT maintains a documented incident response process. Security incidents are detected, assessed, contained, and resolved in accordance with our incident management procedures. Where a data breach affects personal data, we will notify the Data Protection Commission and affected individuals as required by GDPR Articles 33 and 34.

Supplier Management

ECAT assesses and monitors the security posture of our key suppliers and service providers. Our supplier management framework includes security requirements in contracts, regular reviews, and ongoing monitoring to ensure our supply chain meets our information security standards.

Business Continuity

ECAT’s cloud-first architecture provides inherent resilience through our cloud platform’s availability zones and redundant infrastructure. We maintain a business continuity plan that is reviewed and tested regularly to ensure we can maintain operations during and after disruptive events.

Continuous Improvement

Information security is not a one-time achievement. ECAT operates a Plan-Do-Check-Act (PDCA) cycle with regular internal audits, management reviews, risk assessments, and corrective actions to continually improve our security posture. Our ISMS objectives are set annually and progress is measured against defined key performance indicators.

Contact Us

If you have any questions about our information security practices, please contact us:

 

© 2026 ECAT Electronic Compliance Audit Tools Ltd. All rights reserved.