Information Security and Data Handling
1. Scope
This document describes how Veltrion handles client material, regulatory dossiers and personal information. It is written to answer supplier security assessments honestly, at the scale Veltrion actually operates.
2. Information classification
| Class | Examples | Handling |
|---|---|---|
| Restricted | Unpublished dossiers, regulatory submissions, safety data, pricing | Access on a need-to-know basis, encrypted storage and transfer, never on personal or unmanaged devices |
| Confidential | Client correspondence, scoping material, partner terms | Access limited to the mandate team and engaged partners under written confidentiality terms |
| Internal | Templates, internal method, general research | Internal use |
| Public | Published site content and policies | No restriction |
3. Controls
- Access. Least privilege. Access is granted per mandate and withdrawn when the mandate concludes or a person or partner leaves it.
- Authentication. Multi-factor authentication on business email, storage and any system holding client material.
- Encryption. Encryption in transit for all transfers, and at rest on managed devices and storage.
- Devices. Full-disk encryption, automatic screen lock, current operating system and security updates.
- Transfer. Client material is exchanged through the client's preferred secure channel where they have one. Unencrypted email is not used for Restricted material.
- Backup. Regular backups with restoration tested periodically.
- Disposal. Secure deletion at the end of the retention period set out in the Privacy Notice.
4. Delivery partners
Partners receive only the material required for their specific task. Written confidentiality terms are agreed before any client material is transferred. Partners are required to notify Veltrion without undue delay of any suspected compromise affecting client material.
5. Incident response
- Contain. Isolate affected accounts, devices or channels.
- Assess. Determine what information was involved, whose it was, and the likely consequences.
- Notify. Affected clients are notified without undue delay. Where personal information is compromised, we notify the Information Regulator and affected data subjects as required by section 22 of POPIA, and any equivalent obligation under GDPR.
- Remediate and record. Fix the cause, record the incident and the response, and adjust controls.
We do not delay notification in order to complete an investigation.
6. Use of artificial intelligence tools
This matters because an unverified generated statement about a regulatory requirement is exactly the kind of error that damages a client and cannot be quietly withdrawn.
7. Continuity
Because delivery capacity is contracted rather than carried, continuity depends on documented mandate records rather than on any individual's memory. Mandate files are maintained so that another qualified person can take over the work.
8. Supplier assessments
We complete client security questionnaires and will state plainly where a control is not in place. Requests should be sent to the Information Officer.
Contact
Questions about this document should be directed to info@veltrionlaboratories.com, marked for the attention of the Information Officer.