VeltrionLABORATORIES Start
Governance and policies

Information Security and Data Handling

Effective 4 August 2026 Version 1.0 Applies to All Veltrion information handling and delivery partners Owner Veltrion Laboratories (Pty) Ltd

1. Scope

This document describes how Veltrion handles client material, regulatory dossiers and personal information. It is written to answer supplier security assessments honestly, at the scale Veltrion actually operates.

We describe controls we actually operate. Where a control is aspirational or not yet implemented, we say so rather than claim it. A supplier questionnaire answered optimistically is a misrepresentation.

2. Information classification

ClassExamplesHandling
RestrictedUnpublished dossiers, regulatory submissions, safety data, pricingAccess on a need-to-know basis, encrypted storage and transfer, never on personal or unmanaged devices
ConfidentialClient correspondence, scoping material, partner termsAccess limited to the mandate team and engaged partners under written confidentiality terms
InternalTemplates, internal method, general researchInternal use
PublicPublished site content and policiesNo restriction

3. Controls

  • Access. Least privilege. Access is granted per mandate and withdrawn when the mandate concludes or a person or partner leaves it.
  • Authentication. Multi-factor authentication on business email, storage and any system holding client material.
  • Encryption. Encryption in transit for all transfers, and at rest on managed devices and storage.
  • Devices. Full-disk encryption, automatic screen lock, current operating system and security updates.
  • Transfer. Client material is exchanged through the client's preferred secure channel where they have one. Unencrypted email is not used for Restricted material.
  • Backup. Regular backups with restoration tested periodically.
  • Disposal. Secure deletion at the end of the retention period set out in the Privacy Notice.

4. Delivery partners

Partners receive only the material required for their specific task. Written confidentiality terms are agreed before any client material is transferred. Partners are required to notify Veltrion without undue delay of any suspected compromise affecting client material.

5. Incident response

  1. Contain. Isolate affected accounts, devices or channels.
  2. Assess. Determine what information was involved, whose it was, and the likely consequences.
  3. Notify. Affected clients are notified without undue delay. Where personal information is compromised, we notify the Information Regulator and affected data subjects as required by section 22 of POPIA, and any equivalent obligation under GDPR.
  4. Remediate and record. Fix the cause, record the incident and the response, and adjust controls.

We do not delay notification in order to complete an investigation.

6. Use of artificial intelligence tools

Client Restricted material is not entered into general-purpose public AI services. Where AI assistance is used for internal drafting or research, it is used on internal or public material, and any output that reaches a client document is verified against source by a person before it is used.

This matters because an unverified generated statement about a regulatory requirement is exactly the kind of error that damages a client and cannot be quietly withdrawn.

7. Continuity

Because delivery capacity is contracted rather than carried, continuity depends on documented mandate records rather than on any individual's memory. Mandate files are maintained so that another qualified person can take over the work.

8. Supplier assessments

We complete client security questionnaires and will state plainly where a control is not in place. Requests should be sent to the Information Officer.

Contact

Questions about this document should be directed to info@veltrionlaboratories.com, marked for the attention of the Information Officer.