Information Security Statement
Our commitment to protecting the confidentiality, integrity, and availability of the information entrusted to us.
Statement for Website: Information Security Statement
InBreetic Information Security Commitment
Date: 23/07/2026
Our Commitment to Information Security
InBreetic Technologies Limited is committed to protecting the confidentiality, integrity, and availability of the information entrusted to us by our customers, partners, employees, and other stakeholders. Information security is a core part of how we operate, not an afterthought.
How We Protect Your Information
Governance and Accountability
Our management team has ultimate responsibility for information security, supported by a dedicated ISMS Manager who oversees our security program and reports regularly on its effectiveness.
Data Classification and Handling
All information we handle is classified according to its sensitivity and managed in line with defined handling procedures. Access to sensitive information is restricted to authorised personnel with a legitimate business need.
Access Control
We enforce strict access controls across all our systems, including multi-factor authentication, role-based access, and the principle of least privilege. Access rights are reviewed quarterly and revoked immediately upon staff departure.
Encryption
All sensitive data is encrypted in transit and at rest using industry-standard cryptographic algorithms including AES-256. All data transmitted over public networks uses TLS 1.2 or higher.
Third-Party Security
All third-party providers who handle data on our behalf are subject to formal due diligence, contractual security obligations, and periodic vendor risk assessments. We require all third parties to maintain security standards consistent with our own.
Incident Management
We maintain a formal incident response programme with defined escalation procedures, 24/7 monitoring capabilities, and clear notification processes. In the event of a security incident affecting your data, we will notify affected parties in accordance with applicable regulatory requirements.
Regulatory Compliance
InBreetic Technologies Limited operates in accordance with applicable Nigerian regulatory requirements including the Nigeria Data Protection Act (NDPA), General Application and Implementation Directive (GAID) 2025, Nigeria Revenue Service (Establishment) Act, 2025 (the Act) and Companies and Allied Matters Act (CAMA) 2020.
Security Awareness
All staff complete mandatory information security awareness training upon joining and annually thereafter. Our security programme is continuously updated to address the evolving threat landscape.
Our Information Security Objectives
We are committed to achieving the following Information Security Objectives:
- Protecting our customers' financial and personal information through the implementation of appropriate technical, organizational, and administrative security controls while complying with applicable data protection, privacy, legal, regulatory, and contractual requirements.
- Delivering secure, resilient, and reliable services by maintaining robust security measures that support the availability, integrity, and resilience of our critical business processes and technology infrastructure.
- Embedding information security throughout the design, development, testing, deployment, and maintenance of our products and services by adopting secure software development and change management practices.
- Maintaining effective business continuity and disaster recovery capabilities to ensure the timely recovery of critical services and minimize the impact of operational disruptions.
- Strengthening our cybersecurity capabilities through continual monitoring, risk management, threat detection, incident response, and the adoption of appropriate security technologies and industry best practices.
- Promoting a strong culture of information security by providing ongoing awareness, education, and role-based training to ensure that all personnel understand and fulfil their information security responsibilities.
- Continually improving the effectiveness of our Information Security Management System through regular risk assessments, internal audits, management reviews, performance monitoring, and the implementation of corrective and preventive actions.
Your Responsibilities as a Partner or Customer
We ask that organisations working with InBreetic Technologies Limited uphold equivalent information security standards when handling any data shared with them. All third-party agreements with InBreetic Technologies Limited include explicit data protection and security obligations.
Contact Us
For information security enquiries, responsible disclosure, or to report a security concern, please contact us at: support@breet.io
InBreetic Technologies Limited is committed to maintaining the confidentiality, integrity, and availability of all information in our care. Our information security practices are reviewed and updated regularly to reflect changes in the threat landscape, regulatory requirements, and business objectives.