1. Scope
This document describes how Veltrion handles client material, regulatory dossiers and personal
information. It is written to answer supplier security assessments honestly, at the scale Veltrion
actually operates.
We describe controls we actually operate. Where a control is aspirational or not
yet implemented, we say so rather than claim it. A supplier questionnaire answered optimistically is a
misrepresentation.
2. Information classification
| Class | Examples | Handling |
| Restricted | Unpublished dossiers, regulatory submissions, safety data, pricing | Access on a need-to-know basis, encrypted storage and transfer, never on personal or unmanaged devices |
| Confidential | Client correspondence, scoping material, partner terms | Access limited to the mandate team and engaged partners under written confidentiality terms |
| Internal | Templates, internal method, general research | Internal use |
| Public | Published site content and policies | No restriction |
3. Controls
- Access. Least privilege. Access is granted per mandate and withdrawn when the mandate concludes or a person or partner leaves it.
- Authentication. Multi-factor authentication on business email, storage and any system holding client material.
- Encryption. Encryption in transit for all transfers, and at rest on managed devices and storage.
- Devices. Full-disk encryption, automatic screen lock, current operating system and security updates.
- Transfer. Client material is exchanged through the client's preferred secure channel where they have one. Unencrypted email is not used for Restricted material.
- Backup. Regular backups with restoration tested periodically.
- Disposal. Secure deletion at the end of the retention period set out in the Privacy Notice.
4. Delivery partners
Partners receive only the material required for their specific task. Written confidentiality terms
are agreed before any client material is transferred. Partners are required to notify Veltrion without
undue delay of any suspected compromise affecting client material.
5. Incident response
- Contain. Isolate affected accounts, devices or channels.
- Assess. Determine what information was involved, whose it was, and the likely consequences.
- Notify. Affected clients are notified without undue delay. Where personal information is compromised, we notify the Information Regulator and affected data subjects as required by section 22 of POPIA, and any equivalent obligation under GDPR.
- Remediate and record. Fix the cause, record the incident and the response, and adjust controls.
We do not delay notification in order to complete an investigation.
6. Use of artificial intelligence tools
Client Restricted material is not entered into general-purpose public AI services.
Where AI assistance is used for internal drafting or research, it is used on internal or public material,
and any output that reaches a client document is verified against source by a person before it is used.
This matters because an unverified generated statement about a regulatory requirement is exactly the
kind of error that damages a client and cannot be quietly withdrawn.
7. Continuity
Because delivery capacity is contracted rather than carried, continuity depends on documented mandate
records rather than on any individual's memory. Mandate files are maintained so that another qualified
person can take over the work.
8. Supplier assessments
We complete client security questionnaires and will state plainly where a control is not in place.
Requests should be sent to the Information Officer.
Questions about this document should be directed to
info@veltrionlaboratories.com,
marked for the attention of the Information Officer.