1. Security principles
Security relies on least access, environment separation, traceability, backups and continuous improvement. This page describes operational practices and claims no ISO, HDS, PCI DSS or other certification that has not been formally obtained.
2. Establishment separation
Each establishment uses a distinct data environment. Administration and support operations are limited to the necessary scope and must not mix tenant data.
3. Identities and permissions
Access is individual and role-based. Passwords are protected through appropriate hashing, sessions are controlled and sensitive actions may require additional checks. Unneeded accounts must be disabled promptly.
4. Transport, secrets and payments
Public exchanges use HTTPS. Technical secrets are kept separate from code and protected from logs and interfaces. Complete payment-card data is entered with the payment provider and is not retained by Ikelo.
5. Logging and detection
Sign-ins, errors and sensitive actions may be logged to diagnose incidents, detect abuse and establish a timeline. Log access is limited and retention proportionate.
6. Backups and continuity
Backups, availability checks and recovery procedures support operations. They reduce risk without guaranteeing that no incident or interruption can occur.
7. Providers and incidents
Providers are selected for their function and available safeguards. An incident is assessed, contained, documented and corrected. Customers and authorities are notified where required by law or risk.
8. Report a vulnerability
Send a reproducible description to contact@ikelo.pro without accessing data that is not yours, disrupting the service or publishing details before remediation. Include the URL, observed impact and minimum reproduction steps.