Policy
Data Security Policy
Illume security practices for CMS content, admin accounts, media assets, contact submissions, and product delivery data.
Security baseline
Illume uses role-based admin access, hashed passwords, HTTPS, protected API routes, environment-managed secrets, database backups, logging, and least-privilege operational access where practical.
Production infrastructure should use secure reverse proxy configuration, SSL certificates, firewall controls, and restricted administrative access.
Incident handling
Security incidents are triaged for scope, impact, containment, recovery, and notification obligations.
Where applicable, incident reporting and log retention should consider CERT-In directions, contractual duties, and client-specific notification requirements.
Data retention
Contact submissions, project records, invoices, and CMS audit information are retained only as long as required for business, legal, security, tax, and contractual purposes.
Deletion requests are assessed against legal retention needs and active service obligations.