Security Policy
Last updated: December 23, 2025
Rorejue is committed to protecting the security of its platform, services, and the data entrusted to us by our users. This Security Policy describes the technical and organizational measures we implement to safeguard information processed through rorejue.pro.
1. Scope
This policy applies to all systems, infrastructure, applications, and processes operated by Rorejue in connection with the delivery of its online educational services. It covers data in transit, data at rest, access controls, incident response, and third-party relationships.
2. Data Protection Principles
We apply the following core principles when handling user data:
- Confidentiality: Access to data is restricted to authorized personnel and systems with a legitimate operational need.
- Integrity: We implement controls to prevent unauthorized modification or corruption of data.
- Availability: We design our systems to remain accessible and resilient, minimizing unplanned downtime.
3. Infrastructure Security
3.1 Hosting and Network
Our platform is hosted on infrastructure that maintains industry-recognized security certifications. Network traffic is segmented and monitored. Firewalls and intrusion detection mechanisms are in place to identify and block unauthorized access attempts.
3.2 Encryption
All data transmitted between users and our platform is encrypted using TLS 1.2 or higher. Sensitive data stored within our systems is encrypted at rest using established cryptographic standards. Encryption keys are managed through dedicated key management procedures with restricted access.
3.3 System Hardening
Servers and services are configured following security hardening guidelines. Unnecessary services, ports, and protocols are disabled. Operating systems and software dependencies are kept up to date with security patches applied on a regular basis.
4. Access Control
4.1 Authentication
Access to internal systems requires strong authentication. Where available, multi-factor authentication is enforced for administrative and privileged accounts. Passwords are stored using one-way hashing algorithms with appropriate salting.
4.2 Principle of Least Privilege
Personnel are granted access only to the systems and data necessary to perform their specific responsibilities. Access rights are reviewed periodically and revoked promptly upon role change or termination.
4.3 Audit Logging
Access to sensitive systems and data is logged. Logs are retained for a defined period and protected against unauthorized modification. Logs are reviewed as part of routine security monitoring and incident investigation.
5. Application Security
5.1 Secure Development
Our development practices incorporate security considerations throughout the software lifecycle. Code changes are reviewed before deployment. We follow established guidelines to prevent common vulnerabilities including injection attacks, cross-site scripting, and insecure direct object references.
5.2 Vulnerability Management
We conduct periodic security assessments of our platform. Identified vulnerabilities are prioritized and remediated according to their severity. We maintain a process for receiving and evaluating security disclosures from external researchers.
5.3 Dependency Management
Third-party libraries and components used in our platform are monitored for known vulnerabilities. Updates and patches are applied in a timely manner to reduce exposure to publicly disclosed risks.
6. Incident Response
We maintain a documented incident response process that covers detection, containment, investigation, remediation, and notification. In the event of a security incident that affects user data, we will notify affected users and relevant parties in accordance with applicable obligations and within a reasonable timeframe.
If you believe you have discovered a security vulnerability in our platform, please contact us at [email protected] with a description of the issue. We ask that you refrain from publicly disclosing the vulnerability until we have had a reasonable opportunity to investigate and address it.
7. Physical Security
Data processing facilities used by our infrastructure providers implement physical access controls including restricted entry, surveillance, and environmental safeguards. Our own office premises at Szczytowa 23, 42-216 Częstochowa, Poland are secured against unauthorized physical access.
8. Third-Party Service Providers
We engage third-party vendors to support the delivery of our services. Before engaging a vendor with access to user data, we assess their security practices. Vendors are required to maintain appropriate security standards and are bound by contractual obligations regarding data protection and confidentiality.
9. Employee Security
All personnel with access to user data receive security awareness training. Staff are required to follow internal security policies and procedures. Background checks are conducted where appropriate and permitted by applicable requirements.
10. Business Continuity and Backup
We maintain backup procedures to support recovery of data in the event of system failure or data loss. Backups are stored securely and tested periodically to verify their integrity and recoverability. Business continuity plans are in place to support continued service delivery under adverse conditions.
11. Monitoring and Testing
Our systems are subject to continuous monitoring for anomalous activity, performance degradation, and potential security events. Automated alerts are configured to notify responsible personnel of conditions that may indicate a security concern. Security controls are tested and reviewed on a regular basis.
12. Data Retention and Disposal
Data is retained only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable obligations. When data is no longer needed, it is disposed of securely using methods appropriate to the sensitivity of the information.
13. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. The date at the top of this document indicates when the policy was last revised. Continued use of our platform following any update constitutes acceptance of the revised policy.
14. Contact
Questions or concerns regarding this Security Policy may be directed to us using the following contact details: