Security Policy

Last updated: July 31, 2026

This Security Policy describes the measures Nykyreu takes to protect the confidentiality, integrity, and availability of data processed through its platform and services. By using our services, you acknowledge that you have read and understood this policy.


1. Scope

This policy applies to all systems, infrastructure, software, and processes operated by Nykyreu, including the web platform accessible at nykyreu.com, associated APIs, administrative tools, and any third-party services integrated into our operations. It covers all data processed on behalf of users, learners, instructors, and organizational clients.


2. Information We Protect

Nykyreu applies security controls to the following categories of information:


3. Security Controls

3.1 Encryption

All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS) with a minimum version of TLS 1.2. Sensitive data stored at rest, including credentials and personal records, is encrypted using industry-standard algorithms. Encryption keys are managed separately from the data they protect and are rotated on a defined schedule.

3.2 Access Control

Access to production systems and user data is restricted to authorised personnel only. We enforce the principle of least privilege, granting employees and contractors only the minimum level of access required to perform their responsibilities. All administrative access requires multi-factor authentication and is logged for audit purposes.

3.3 Authentication

User accounts are protected by password-based authentication with enforced complexity requirements. We offer multi-factor authentication as an additional layer of protection. Passwords are stored using one-way cryptographic hashing with salting. Failed login attempts are monitored and rate-limited to prevent brute-force attacks.

3.4 Network Security

Our infrastructure is protected by firewalls, intrusion detection systems, and network segmentation. Public-facing services are isolated from internal systems. We conduct regular vulnerability scans and apply security patches in accordance with our patch management schedule. Distributed denial-of-service protections are applied at the network perimeter.

3.5 Application Security

Our development practices incorporate security at every stage of the software lifecycle. Code is reviewed for security vulnerabilities before deployment. We conduct periodic penetration testing and address findings according to severity. Input validation, output encoding, and protection against common web vulnerabilities including those described in the OWASP Top Ten are standard requirements for all application components.

3.6 Physical Security

Our services are hosted in data centres that maintain physical access controls including badge-based entry, surveillance systems, and environmental monitoring. Physical access to server hardware is restricted to authorised data centre personnel. We do not operate our own physical server facilities.


4. Third-Party Service Providers

We engage third-party providers to support infrastructure, payment processing, communication, and analytics functions. All third-party providers are evaluated for their security practices prior to engagement. We require that providers maintain appropriate technical and organisational security measures consistent with this policy. Data shared with third parties is limited to what is necessary for the service being provided.


5. Data Retention and Deletion

We retain user data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable obligations. When data is no longer required, it is securely deleted or anonymised using methods that prevent reconstruction. Users may request deletion of their personal data by contacting us at the address provided in this policy.


6. Security Monitoring and Logging

We maintain logs of system activity, authentication events, and administrative actions. Logs are stored securely and reviewed regularly to detect anomalous behaviour or potential security incidents. Automated alerting is configured for events that may indicate unauthorised access or system compromise. Log data is retained for a defined period and is accessible only to authorised personnel.


7. Incident Response

7.1 Detection and Containment

We maintain an incident response process to address security events in a timely and structured manner. Upon detection of a potential security incident, our team initiates containment measures to limit the scope of impact and preserve evidence for investigation.

7.2 Notification

In the event of a confirmed security incident that affects user data, we will notify affected users without undue delay using the contact information associated with their account. Notifications will include a description of the nature of the incident, the categories of data involved, the likely consequences, and the measures taken or proposed to address the incident.

7.3 Post-Incident Review

Following the resolution of a security incident, we conduct a post-incident review to identify root causes, evaluate the effectiveness of our response, and implement improvements to prevent recurrence.


8. Business Continuity and Disaster Recovery

We maintain business continuity and disaster recovery plans to ensure the availability of our services in the event of system failure, data loss, or other disruptive events. Critical data is backed up regularly, and backups are stored in geographically separate locations. Recovery procedures are tested periodically to verify their effectiveness.


9. Employee Security Practices

All employees and contractors with access to user data or internal systems receive security awareness training upon onboarding and on a recurring basis. Personnel are required to follow acceptable use policies and to report suspected security incidents immediately. Access privileges are reviewed regularly and revoked promptly upon termination of employment or contract.


10. Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities identified in our platform. If you discover a potential security issue, please contact us directly at contact@nykyreu.com before disclosing it publicly. We commit to acknowledging your report promptly, investigating the issue in good faith, and communicating our findings and remediation timeline. We ask that you do not access, modify, or disclose data belonging to other users during your research.


11. Organisational Governance

Security responsibilities are assigned to designated personnel within our organisation. Security policies and controls are reviewed at least annually and updated to reflect changes in our services, technology landscape, and risk environment. We assess security risks on an ongoing basis and prioritise controls according to potential impact.


12. Changes to This Policy

We may update this Security Policy from time to time to reflect changes in our practices, technologies, or obligations. When we make material changes, we will update the date at the top of this page and, where appropriate, notify users through the platform or by email. Continued use of our services following the posting of changes constitutes acceptance of the revised policy.


13. Contact

If you have questions, concerns, or requests relating to this Security Policy or our security practices, please contact us:

Nykyreu

40 Mhainéar an Tobair Naofa, Feltrim Hall, Swords, Co. Dublin, Ireland

Email: contact@nykyreu.com

Phone: +353 89 700 9590