(a) The Service Provider shall maintain a commercially reasonable information-security programme designed to protect the confidentiality, integrity, and availability of BlockchainCert and Subscriber Data processed by the Service Provider.
(b) The programme shall include administrative, technical, and organisational safeguards appropriate to the nature of the Covered Services, the data processed, and the associated risks.
(c) Upon the Subscriber’s written request and subject to confidentiality obligations, the Service Provider may make available reasonable security documentation or summaries of its security practices, where available and appropriate.
The Service Provider shall implement and maintain commercially reasonable security controls, which may include the following:-
| Security Control | Requirement |
|---|---|
| Encryption in transit | The Service Provider shall use commercially reasonable encryption protocols for external interfaces, where applicable. |
| Encryption at rest | The Service Provider shall apply encryption or other appropriate safeguards for sensitive Subscriber Data stored in Service Provider-controlled systems, where applicable. |
| Access control | The Service Provider shall maintain access controls designed to restrict access to Subscriber Data and production systems to authorised personnel only. |
| Identity and access management | The Service Provider shall apply role-based access control and the principle of least privilege for access to production systems, where reasonably practicable. |
| Vulnerability management | The Service Provider shall maintain reasonable vulnerability management and patching processes based on severity, risk, and operational impact. |
| Application security | The Service Provider shall apply reasonable secure development practices in the design, development, testing, and deployment of the Services. |
| Security testing | The Service Provider may conduct security testing, vulnerability assessments, or penetration testing from time to time as the Service Provider considers appropriate. |
The Service Provider’s personnel with access to Subscriber Data shall be subject to appropriate confidentiality obligations and internal security requirements. The Service Provider may provide security-awareness or data-protection training to relevant personnel under its policies and procedures.
(a) The Service Provider shall notify the Subscriber without undue delay after becoming aware of a security incident that materially affects Subscriber Personal Data or Subscriber Confidential Information and, where applicable, in sufficient time to support the Subscriber’s statutory notification deadlines.
(b) The Service Provider shall provide information reasonably available regarding:-
(i) the nature, date, and likely consequences of the security incident;
(ii) the affected Covered Services, data categories, and approximate data-subject scope, to the extent known;
(iii) the containment, mitigation, remediation, and investigation measures taken or proposed; and
(iv) a contact point and information reasonably required for the Subscriber’s legally required notifications.
(c) The Service Provider shall provide reasonable updates, preserve appropriate incident records, and reasonably assist the Subscriber with its response obligations.
(d) Any notification or cooperation under this Clause 10.4 shall not be construed as an admission of fault or liability by the Service Provider.