Technophobia Logo
Information Security Policy (Public Summary)

Last updated: 14 September 2025

This page summarises how Technophobia Ltd protects data and systems used to deliver our services. It supports our DPA and Sub-processor list.

1. Scope and objectives
  • Applies to staff, contractors, and systems we use for client work.
  • Covers data in our control. Client platforms you own follow your rules.
  • Goals: keep confidentiality, integrity, and availability; meet legal duties; cut risk.
2. Roles and responsibilities
  • Director (Security Lead): policy owner and risk decisions.
  • Project Leads: apply controls on each engagement.
  • All personnel: follow this policy; report incidents fast.
3. Data classification
ClassExamplesHandling
PublicWebsite copy, blog postsNo restriction
InternalRunbooks, non-client docsShare inside team only
Client ConfidentialCredentials, customer records, logsEncrypt in transit; restricted access; store only where needed

We avoid special category data. If needed, we add controls in the SoW.

4. Access control
  • MFA on all admin and code repos.
  • Least-privilege roles; access reviews every 90 days.
  • Joiner/mover/leaver steps with same-day removal on exit.
  • Passwords: 12+ characters; password manager required.
5. Devices and endpoints
  • Company devices only for client credentials.
  • Disk encryption enabled; auto-lock at 5 minutes.
  • OS and browsers patch to current release within 14 days.
  • Anti-malware and DNS filtering active.
6. Network and hosting
  • TLS for data in transit; HTTPS everywhere.
  • Hardened hosts; limited inbound rules; keys rotated on change.
  • Backups for hosted components; restore tests at least twice a year.
7. Application security
  • Secrets kept outside code and CI logs.
  • Code review for risky changes; non-prod testing before live.
  • Dependencies scanned; pin versions; remove unused packages.
8. Logging and monitoring
  • Health checks on workflows and endpoints.
  • Alert on failures, unusual latency, and job queues.
  • Log retention: 30–90 days by default (per client risk).
9. Vulnerability and patching
  • Critical patches within 7 days; high within 14 days.
  • Monthly dependency updates; emergency hotfix path in place.
10. Incident response
  1. Detect: alerts or reports to the Security Lead.
  2. Contain: revoke keys, isolate hosts, switch to backups.
  3. Eradicate/Recover: fix, restore, validate.
  4. Notify: clients without undue delay if personal data is affected (per the DPA).
  5. Review: capture causes and actions.
11. Business continuity
  • Target RTO 8 hours for hosted n8n; RPO 24 hours unless your SoW sets different targets.
  • Documented rollback for key workflows.
12. Supplier management
  • Use reputable providers; short retention where practical.
  • Review data locations and terms. Live list at /sub-processors.
13. Training and awareness
  • Induction security briefing for all personnel.
  • Annual refresh covering phishing, handling data, and incidents.
14. Records and privacy
  • Data maps and SoW notes record where personal data flows.
  • Retention follows our Privacy Policy and project needs.
15. Compliance and review
  • Policy review at least yearly or after major changes.
  • Breaches of this policy may lead to access removal or contract action.
Contact

Questions about this policy?

Technophobia Ltd · Company No. 14898332 · VAT GB 495 7043 58
13B Devonshire Road Industrial Estate, Millom, LA18 4JS, United Kingdom
+44 1229 774591hello@technophobia.uk

Technophobia

n8n automation for small teams. UK-based. Fast turnarounds. Clear handovers.

Address
South Cumbria Skills Exchange
Millom
LA18 4JS
United Kingdom

Phone +44 01229 774591
Email hello@technophobia.uk

VAT registered • GDPR-aligned • Typical lead time: 1–2 business days