Security & Data Protection Policy

Last Updated: June 1, 2026

At Numerikraft, we recognize that security is more than a technical requirement, it is the foundation of digital trust. Our clients, whether in scientific research, healthcare, corporate innovation, or creative industries, entrust us with assets that are often confidential and strategically sensitive. Protecting these assets is not optional; it is at the core of our mission.

This policy sets forth the principles, practices, and safeguards we apply across all our projects. By embedding security into every step of our work, we ensure that our clients can innovate, communicate, and operate with full confidence that their information remains safe, resilient, and respected.

Our Security Philosophy

We follow a defense-in-depth approach, where security is not one barrier but a series of reinforced layers. At the heart of this philosophy are three commitments:

  • Confidentiality: Only authorized individuals can access sensitive information, ensuring discretion and protection at all times.
  • Integrity: Data, research findings, and digital deliverables remain authentic, consistent, and unaltered by unauthorized actors.
  • Availability: Systems, platforms, and files are accessible whenever our clients need them, safeguarded against downtime or disruption.

This approach reflects the guidance of internationally recognized standards such as ISO/IEC 27001. For us, security is not restrictive; it is an enabler of innovation, allowing our partners to focus on their work while we safeguard the foundations.

Data Classification & Lifecycle Management

Not all data requires the same level of protection. To ensure clarity and discipline, we apply a data classification system that defines how each category is handled:

  • Public Data: Content designed for broad visibility, such as websites, promotional materials, or press releases.
  • Confidential Data: Internal strategies, prototypes, and non-public drafts that require restricted access.
  • Highly Sensitive Data: Intellectual property, scientific datasets, financial records, or patient-related content requiring maximum safeguards.

Each category follows strict rules for storage, sharing, and retention. Sensitive files are encrypted both in transit and at rest, while public-facing content is secured to prevent unauthorized modification.

We also embrace the concept of the data lifecycle, ensuring that every file or dataset is properly created, used, archived, and, when no longer needed, securely destroyed. This aligns with global best practices outlined by the OWASP Data Protection Guidelines.

Infrastructure & Secure Technologies

The resilience of our operations is reinforced by industry-leading infrastructure. We partner only with providers who meet internationally recognized certifications such as ISO/IEC 27001 or SOC 2 Type II, ensuring that the platforms we rely on are independently audited for security excellence.

Key safeguards include:

  • End-to-end encryption, protecting information whether it is in motion or at rest.
  • Two-factor authentication (2FA), applied to all critical accounts and services.
  • Automated backup systems, with geographically distributed storage for redundancy.
  • Version control environments, enabling integrity, rollback, and accountability across development workflows.
  • Continuous patching and updates, minimizing exposure to new and emerging vulnerabilities.

Our cloud hosting partners are chosen with care, prioritizing resilience, redundancy, and transparency. These technical safeguards align with frameworks such as the NIST Cybersecurity Framework, ensuring our clients' assets remain protected against evolving digital threats.

Collaborators & Third-Party Access

While Numerikraft primarily operates as a specialized consultancy, some projects require the involvement of external collaborators or subject-matter experts. In these cases, we enforce strict policies to ensure that the chain of trust is never compromised:

  • Access is granted on a least-privilege basis, meaning contributors only see the information they need to fulfill their task.
  • All collaborators operate under confidentiality agreements that bind them to the same standards we uphold.
  • Third-party platforms and tools undergo rigorous security assessments before adoption.
  • Accountability remains centralized with Numerikraft, ensuring clients never assume risk due to third-party actions.

By embedding these safeguards, we maintain an environment where collaboration enhances outcomes without ever compromising data protection.

Incident Response & Resilience

We recognize that no system is immune to potential threats. What defines a secure organization is its capacity to anticipate, respond, and recover effectively.

Our incident response framework includes:

  • 24/7 monitoring of critical systems and workflows.
  • Clear escalation paths, ensuring rapid reaction to anomalies or potential breaches.
  • Client transparency protocols, guaranteeing that partners are informed promptly and honestly if an incident occurs.
  • Post-incident reviews, ensuring that lessons are embedded into stronger future protections.

This proactive resilience strategy reflects the principles outlined in the NIST Cybersecurity Framework, ensuring that our clients experience minimal disruption and maximum continuity.

Compliance & Continuous Improvement

Security is not static, it evolves as new threats emerge and new technologies arise. We remain aligned with international best practices as well as national regulations, including the ANPDP.

To maintain this alignment, we conduct:

  • Periodic internal audits, testing our own resilience.
  • Policy reviews and updates, ensuring relevance with the changing cybersecurity landscape.
  • Knowledge tracking, staying current with updates from organizations like OWASP and ISO.

This culture of continuous improvement allows us to anticipate risks rather than simply react to them.

Secure Development Practices

All of our digital products, from websites and platforms to applications and automation tools, are built with security by design in mind. Security is not added after development but embedded from the very beginning.

We implement:

  • Code reviews and peer validation, ensuring integrity across every line of code.
  • Static and dynamic testing (SAST/DAST) to detect vulnerabilities before deployment.
  • Dependency checks, identifying risks in third-party libraries.
  • Secure configuration management, ensuring environments cannot be exploited by default settings.

Our methodology aligns with the principles of the OWASP Software Assurance Maturity Model (SAMM), ensuring that innovation never comes at the cost of security.

Client Empowerment & Shared Responsibility

While we take full responsibility for securing our environment, we also recognize that security is a shared journey. Clients play an essential role in maintaining resilience by following best practices, such as safeguarding credentials, using strong authentication, and reporting anomalies promptly.

To support this, we provide:

  • Security awareness resources, tailored to project-specific needs.
  • Guidelines on safe collaboration, including secure file transfers and communication channels.
  • Dedicated points of contact, ensuring that clients can escalate questions or concerns quickly.

This partnership model reinforces the trust that underpins our work.

Transparency & Accountability

We believe that trust is strengthened by clarity and openness. Security policies that remain opaque serve no one; instead, we make our standards, commitments, and practices accessible to all stakeholders.

This includes:

  • Clear documentation, explaining how data is handled across the entire lifecycle.
  • Open communication channels, allowing clients to request clarifications at any stage.
  • Accountability mechanisms, ensuring that any deviation from policy is reported, reviewed, and corrected.

Transparency is more than a promise, it is a governance principle that ensures Numerikraft remains accountable not only to its clients but also to regulatory authorities such as the ANPDP and to the global standards community shaping digital trust.

Contact

For any concerns, incident reports, or questions regarding event participation or data handling, please reach out to our dedicated coordination team:

Email: privacy@numerikraft.com

Address: 06 les vergers 01, Birkhadem, Algiers

Business Owner: Sid Ahmed Mili