9:00 - 5:00

Mon - Fri

(562) 441-2195

 

(877) 567-3990

Enterprise Information Security & Privacy Policy

Effective Date: January 2026

Download Policy (PDF)

Enterprise Information Security

Information Security & Access Control Policy

  • Purpose: To protect the confidentiality, integrity, and availability of system assets, legal case files, and client data.
  • Data Classification: All data containing Workers' Compensation claims, PHI, or PII is classified as Restricted / Confidential.
  • Access Control: Access to EAMS processing, source code, and servers is restricted to authorized engineering personnel using the principle of least privilege.
  • Account Management: Unique accounts are required for all users; generic/shared accounts are prohibited and are disabled upon termination.
  • Multi-Factor Authentication: MFA is strictly required for all platform access.

Password & Authentication Policy

  • Complexity: Passwords must be at least 8 characters long, including uppercase, lowercase, numbers, and special characters.
  • Rotation: Administrative passwords must be rotated at least every 60 days, with the last 5 historical passwords restricted from reuse.
  • Lockout: Accounts are locked for 30 minutes after five consecutive failed attempts.

Technical Data Protection & Encryption Policy

  • Encryption: Transit traffic is encrypted via TLS 1.2+ (HTTP forced to HTTPS); data at rest is encrypted using AES-256.
  • Monitoring: Logs are captured continuously and retained for at least one year.
  • Supply Chain: A dynamic Software Bill of Materials (SBOM) is maintained to track and patch third-party dependencies.
  • Sessions: Web sessions terminate after 60 minutes of inactivity; backend access requires a secret key.

Incident Response Policy

  • Identification: Security incidents include unauthorized access, data exposure, or policy violations.
  • Leadership: The Response Leads are Daniel Lopez (CEO) and Khalid Mahmood (Chief Technology Architect).
  • Breach Notification: Confirmed breaches involving unencrypted PHI will be reported to covered entities within 24 to 48 hours.

Backup, Disaster Recovery & Data Retention

  • Backups: Full encrypted (AES-256) backups are performed three times daily in a geographically redundant environment.
  • Recovery Targets: Recovery Point Objective (RPO) is 4 hours; Recovery Time Objective (RTO) is 24 hours.
  • Retention: Active data is kept for the term of the agreement; regulatory submission logs are retained as legally mandated.

Corporate Compliance & Employee Security

  • Agreements: All personnel must sign a binding NDA and Confidentiality Agreement prior to system access.
  • Training: Mandatory Security Awareness and HIPAA training is required upon hire and annually thereafter.
  • Subcontractors: Third parties touching PHI must sign a Business Associate Agreement (BAA).

Privacy Notice

A privacy policy matters immensely for a company for a multitude of reasons, spanning legal compliance, building trust, and protecting the company's reputation.

EdexCloud respects the privacy of its users and is committed to protecting their personal information. This Privacy Notice explains how we collect, use, and disclose information about our users.

Image

INFORMATION WE COLLECT

  • We collect information you provide to us when you register for a user account, use our Services, or communicate with us.
  • The information we collect may include your name, email address, phone number, billing address, and other contact information.
  • We may also collect information on use of rendered services, including your IP address, browser type, and device type.

HOW WE USE INFORMATION

  • We may use the information we collect to personalize your experience on rendered services and to provide support and customer service.

HOW WE DISCLOSE INFORMATION

  • We may disclose your information to comply with legal requirements, to protect our rights or property, or to protect the safety of our users or others.
  • We may disclose your information with your consent only.

DATA RETENTION

  • We will retain your information for as long as necessary to provide our Services to you and as otherwise necessary to comply with legal obligations, resolve disputes, and enforce our agreements.

YOUR CHOICES

  • You may choose not to provide certain information to us, but this may limit your ability to use our Services.

OUR COMMITMENT TO YOUR SECURITY

We take reasonable measures to protect the security of your information.
  • Secure Transactions with SSL/TLS Encryption:

    Every interaction on our website, especially when you're entering sensitive details like payment information, is protected by industry-standard SSL/TLS (Secure Socket Layer/Transport Layer Security) encryption. This means that any data transmitted between your browser and our website is encrypted, making it unreadable to unauthorized parties. You'll see "https://" in your browser's address bar and often a padlock icon, indicating a secure connection.

  • Trusted Payment Processing:

    We don't directly store your sensitive payment card details on our servers. Instead, all credit card transactions are handled by trusted, third-party payment gateways. These providers are leading experts in secure online payments and are PCI DSS compliant, meaning they adhere to the highest security standards for handling payment card information. Your card details are securely transmitted directly to them, ensuring maximum protection.

  • Data Protection and Privacy:

    Beyond payment security, we are committed to protecting your personal data to safeguard your information.

  • Eligible Region:

    All of our services are available to U.S. region only.

Payment/Refund Policy

To ensure fairness and clarity, here are the general terms and conditions that apply to our payment or refund policy.
  • Subscription Validity Period:

    Each subscription is valid for a pre-defined period. Your subscription will not auto-renew. Once your plan expires or you reach your quota, you can renew it at any time by making a new payment.

  • No Recurring payment:

    For your security and control, we don't store your payment information for recurring charges. You'll need to manually make a payment each time you wish to renew your subscription.

  • Void/Refund:

    If you have subscribed by accident and have not yet used our WCAB services, you are eligible for a refund upon request. We will void or refund your payment according to the payment gateway's rules.

  • Right to Cancel:

    We reserve the right to cancel a subscription if we find any fraudulent or abusive activity or violation to our terms of service.

  • Currency:

    We only accept U.S. dollars.

  • Payment Methods:

    We support the following payment methods.

UPDATES TO THIS PRIVACY NOTICE

  • We may update this Privacy Policy Notice from time to time. The updated Privacy Policy Notice will be posted on our website.

If you have any questions about our Privacy Policy Notice, please contact us at [email protected].