Legal
Information Security Policy
Last updated: 10 June 2026
Our clients trust us with some of their most sensitive information: vulnerability findings, test results, forensic evidence and threat intelligence. This page sets out the commitments our top management has made to protect that information, and the objectives we measure ourselves against. It summarises our Information Security Policy, which forms part of our Information Security Management System (ISMS), built to the requirements of ISO/IEC 27001:2022.
1. Scope
Our ISMS covers the cybersecurity consultancy, security solutions, training and certification services, and the ThreatSeal, Corevex Range and Redpherix platforms delivered by Enovise Group from our Nairobi Headquarters office, from client sites and from approved remote working locations in Kenya.
2. Our Commitments
Enovise Group top management commits to the following.
- Meeting our obligations. We identify and meet the legal, statutory, regulatory and contractual requirements that apply to information security in the jurisdictions where we operate, and keep them under regular review. These include data protection and cybersecurity laws, and the security commitments we make to our clients.
- Managing risk. We identify, assess and treat information security risks using a defined methodology that takes account of our context, our clients and other interested parties, and we choose our controls on the basis of that assessment.
- Protecting information. We protect the confidentiality, integrity and availability of our own information, and of the information our clients entrust to us, in line with its classification from creation to disposal.
- Testing only with authorisation. We carry out vulnerability assessment, penetration testing and red team work only with the client's written authorisation and within an agreed scope.
- Reporting without fear. Our people and partners report information security events and weaknesses without delay. Anyone who reports in good faith is protected from reprisal.
- Improving continually. We provide the people, budget and resources the ISMS needs, and improve it continually using monitoring results, audit findings, incidents and the lessons drawn from them, and management review.
3. Our Information Security Objectives
We set objectives that can be measured, and top management reviews progress against them.
| No. | Objective | Target |
|---|---|---|
| 01 | Certification | Achieve ISO/IEC 27001:2022 certification for our ISMS. |
| 02 | People | Every member of staff and every contractor trained, with this policy acknowledged. |
| 03 | Access | Multi-factor authentication on every business account. |
| 04 | Risk | No critical or high information security risk left untreated. |
| 05 | Response | Every security alert from our product monitoring triaged by the next business day. |
4. Responsibility
Our Group CEO approves this policy, and our Chief Information Security Officer is responsible for the ISMS. Everyone who works with Enovise or client information, including staff, contractors and partners, is required to follow it.
5. Reporting a Security Concern
If you believe you have found a vulnerability in our website, ThreatSeal, Corevex Range or Redpherix, or have a security concern about Enovise, email csirt@enovise.com. Please describe what you found and how to reproduce it, and do not test our systems without our written permission. We acknowledge reports by the next business day.
6. Review of This Policy
We review this policy at least once a year, and whenever our business, our risks, or the law change. The “Last updated” date above shows when it was last revised. Clients and other interested parties may request a copy of the full policy.
7. Contact Us
For questions about this policy, contact csirt@enovise.com. For questions about your personal data, contact dpo@enovise.com or see our Privacy Policy. For cookies, see our Cookie Policy.