Data & Security
How we protect your data and the systems we build.
Infrastructure Security
All CRES Dynamics systems and client projects are hosted on infrastructure that meets international security standards. We use encrypted connections (TLS 1.3), firewalls, and regular security audits to protect data at rest and in transit.
Access Control
We implement role-based access control (RBAC) across all systems. Team members only have access to the data they need to perform their roles. Admin access requires multi-factor authentication and is logged for audit purposes.
Data Encryption
All sensitive data is encrypted using AES-256 at rest and TLS 1.3 in transit. Passwords are hashed using bcrypt with appropriate salt rounds. API keys and secrets are stored in environment variables, never in code.
Backup & Recovery
Client databases are backed up daily with 30-day retention. We maintain disaster recovery procedures and can restore systems within 4 hours of a critical failure. Backup data is encrypted and stored in geographically separate locations.
Client Data Ownership
You own your data. CRES Dynamics does not use client data for purposes beyond delivering the agreed services. Upon project completion and full payment, all client data can be exported and deleted from our systems upon request.
Compliance
We follow OWASP security guidelines for web application development. Client systems are built to comply with the Kenya Data Protection Act 2019 and relevant industry regulations.
Incident Response
In the event of a security incident, we follow a documented incident response plan: immediate containment, investigation, notification to affected parties within 72 hours, and remediation to prevent recurrence.
Contact
For security-related inquiries or to report a vulnerability, contact us at security@cresdynamics.com or call +254 708 805 496.















