Introduction
TCAI Solutions takes the security of its systems, data and services very seriously. This document describes our security measures, our responsible disclosure policy and how we handle security incidents.
This policy applies to all TCAI Solutions services, including tcaisolutions.nl, keciai.nl, TSS (Troubleshoot Solutions) and SignalWise.
Responsible Disclosure
Have you discovered a vulnerability in one of our systems? We appreciate it if you report it to us responsibly so we can fix it.
Send an email to [email protected] with a description of the vulnerability, the steps to reproduce it and any supporting evidence.
What we expect from you
- Do not share the vulnerability with third parties until it has been resolved
- Do not abuse the vulnerability (for example by downloading or modifying data)
- Do not perform attacks that endanger the availability of our services (DoS/DDoS)
- Do not use social engineering, phishing or physical attacks
What you can expect from us
- We confirm your report within 3 working days
- We keep you informed of progress
- We resolve the vulnerability as quickly as possible, within 90 days at the latest
- We will not take legal action against you if you act in good faith
Security measures
We apply extensive technical and organisational measures to protect our systems and your data:
Network security
- SSL/TLS encryption on all connections (HTTPS, TLS 1.2 minimum)
- Web Application Firewall (WAF) via Cloudflare
- DDoS protection on all public endpoints
- VPN-only access for admin panels
- Firewall configuration with minimal open ports
System security
- Regular security updates and patches
- Continuous monitoring of all services (24/7)
- Automated detection of unauthorised access attempts
- Fail2ban protection against brute-force attacks
- Regular security audits and penetration tests
Data security
- Encrypted storage of sensitive data (passwords via bcrypt)
- Access control based on roles and need-to-know
- Encrypted backups
- Logging of all access attempts
NIS2 Compliance
TCAI Solutions complies with the European NIS2 directive (Network and Information Security Directive 2). Among other things, this means:
- Risk management: periodic risk analyses of our systems and processes
- Incident reporting: procedure for timely reporting of security incidents
- Business continuity: measures to safeguard availability
- Supply chain security: assessment of the security of our suppliers
- Encryption: application of encryption where appropriate
- Access control: strict control over who has access to which systems
TCAI Solutions applies the NIS2 directive as the minimum standard for the security of its services. We periodically evaluate our measures and adjust them based on new threats and developments.
Data protection
- All data is stored on servers in the Netherlands and the European Union
- No transfer of personal data outside the EEA without appropriate safeguards
- Encrypted storage and transport of data
- Strict access control: only authorised personnel have access
- Data is never sold to third parties
See our privacy policy for more information on how we handle personal data.
Incident response
In the event of a security incident we follow an established procedure:
- Detection: continuous monitoring automatically detects anomalies
- Classification: the incident is assessed for severity and impact
- Containment: immediate measures to limit the impact
- Investigation: analysis of the cause and scope
- Recovery: return to normal operation
- Evaluation: lessons learned and adjustment of measures
In the event of a data breach that poses risks to data subjects, we report it to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours, in accordance with the GDPR. Data subjects are informed as soon as possible when there is a high risk to their rights and freedoms.
Trademarks
The following names and brands are trademarks of TCAI Solutions:
- TCAI Solutions
- KECIAI
- TSS (Troubleshoot Solutions)
- SignalWise
These trademarks may not be used without written permission from TCAI Solutions. Unauthorised use of our brands infringes our intellectual property rights.
TCAI Solutions
Lelystad, the Netherlands
KvK: 86552937
Contact
For security reports and questions about this policy:
[email protected]
[email protected]
+31 (0) 320 798 133
TCAI Solutions, Lelystad, the Netherlands