Security Policy
Effective Date: March 17, 2026
1. Overview
FY Network Inc. ("FY Network") is committed to maintaining the security of our products, services, and the data entrusted to us. This policy describes our general security practices across all FY Network products.
2. Security Controls
- Encryption: All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256 or equivalent standards provided by our infrastructure partners.
- Access controls: We enforce the principle of least privilege. Access to production systems and data is restricted to authorized personnel and requires multi-factor authentication.
- Secure development: We follow secure coding practices including input validation, output encoding, and dependency scanning. All code changes undergo review before deployment.
- Dependency management: We monitor all dependencies for known vulnerabilities and apply security patches promptly.
- Infrastructure security: Our services run on industry-leading cloud platforms with SOC 2, ISO 27001, and other relevant certifications. We leverage built-in security features including network isolation, automated backups, and monitoring.
3. Vulnerability Management
- Automated vulnerability scanning of dependencies on every build
- Prompt application of security patches to all components
- Monitoring of security advisories from platform providers (Atlassian, Shopify, AWS, Vercel)
- Periodic security reviews of application code and configurations
4. Incident Response
In the event of a security incident, we follow a structured response process:
- Identification: Immediate assessment of scope and impact upon discovery.
- Containment: Swift action to limit the impact, including disabling affected services if necessary.
- Notification: Affected users and relevant platform partners are notified within 72 hours of confirming an incident that impacts user data.
- Remediation: Security patches are developed and deployed with highest priority.
- Post-incident review: Root cause analysis and implementation of preventive measures.
5. HIPAA Compliance (Carelendr)
For healthcare-related data processed through Carelendr, we maintain compliance with the Health Insurance Portability and Accountability Act (HIPAA), including administrative, physical, and technical safeguards. Carelendr infrastructure is designed to meet HIPAA Security Rule requirements with encryption, audit logging, access controls, and Business Associate Agreements where required.
6. Product-Specific Security
Each product has its own security characteristics. See the product-specific security policies for details:
- SprintLedger Security Policy -- Runs entirely on Atlassian Forge with no external servers or data transfers
7. Reporting Security Issues
If you discover a security vulnerability in any FY Network product, please report it immediately:
- Email: admin@fynetwork.com with the subject line "Security Report"
- Include a description of the vulnerability, steps to reproduce, and the potential impact
We will acknowledge receipt within 2 business days and provide an initial assessment within 5 business days. We ask that you give us reasonable time to address the issue before any public disclosure.
8. Changes to This Policy
We may update this Security Policy as our practices evolve. Changes will be posted on this page with an updated effective date.
9. Contact Us
For security-related questions or concerns, contact us:
- Email: admin@fynetwork.com
- Phone: +1 (973) 649-9368
- Location: Flemington, NJ