Document Control Information
Controlled corporate document maintained by Fobisoft Solutions Ltd.
Information Security Policy
This document defines Fobisoft's corporate commitment to information security, governance, privacy and compliance.
Executive Statement
At Fobisoft Solutions Ltd., information security is a fundamental business commitment that underpins every solution we develop, every customer we support and every technology platform we operate. Protecting information is not simply a technical obligation; it is an essential part of maintaining the confidence entrusted to us by healthcare institutions, commercial organisations, partners and every individual whose information we process.
We recognise that information is one of the most valuable assets owned by any organisation. Our responsibility is therefore to ensure that such information remains protected against unauthorised access, disclosure, alteration, destruction or loss while remaining available to authorised users whenever it is legitimately required.
This Information Security Policy establishes the principles, governance framework and minimum security requirements that guide the protection of Fobisoft's information assets, customer information, intellectual property and supporting technology infrastructure across the organisation.
Information security is embedded throughout our software development lifecycle, operational procedures and customer support activities. Through continual improvement, responsible governance and secure engineering practices, we remain committed to safeguarding information today while preparing for the evolving security challenges of tomorrow.
Fobisoft Solutions Ltd. commits to maintaining an effective Information Security Management framework that protects the confidentiality, integrity and availability of information, supports compliance with applicable legal and contractual obligations, and continually strengthens our security posture through governance, technology and employee awareness.
Governance Responsibilities
| Role | Responsibilities |
|---|---|
| Board of Directors | Provides strategic direction, executive oversight, financial stewardship and ensures legal and ethical compliance. |
| Implementation & Technical Director | Owns the Information Security Management System, approves access to critical systems, leads cybersecurity, incident response, software release approvals and disaster recovery planning. |
| Developers | Design, develop, document and maintain secure software while protecting company and customer information. |
| Contractors | Perform only authorised work under confidentiality, NDA and acceptable-use obligations. |
| Client System Administrators | Administer licensed systems, manage users and privileges, coordinate deployment, safeguard server credentials and notify Fobisoft of administrator changes. |
Security Objectives & Guiding Principles
Fobisoft preserves the principles of Confidentiality, Integrity, Availability, Accountability and Resilience.
- Least Privilege
- Defence in Depth
- Secure by Default
- Fail Secure
- Continuous Improvement
Security controls are embedded throughout the software lifecycle rather than added after development.
Information Asset Management
Fobisoft recognises information assets as critical business resources requiring appropriate protection throughout their lifecycle.
| Critical Assets |
|---|
| Source Code |
| Software Designs |
| Hospitum |
| FobiPoS |
| DauLabs |
| Private Git Repositories |
| Customer Databases |
| Encrypted Cloud Backups |
| Licence Systems |
| AI Models |
| API Keys |
| Encryption Keys |
| Digital Certificates |
| Cloud Infrastructure |
| Financial Records |
| Training Materials |
Risk Management Framework
Fobisoft Solutions Ltd. adopts a proactive approach to identifying, assessing, mitigating and continuously monitoring information security risks that may affect the confidentiality, integrity or availability of company and customer information assets.
Security risks are managed through a combination of employee awareness, technical safeguards, operational procedures and resilient recovery capabilities. Risk management forms part of everyday business operations and software development activities rather than being treated as a standalone function.
- Continuous employee security awareness and cyber-security training to reduce social engineering risks.
- Enforcement of strong password standards based on modern passphrase guidance and unique credentials.
- Defined incident response procedures for rapid containment, investigation and recovery from security events.
- Immediate execution of GitHub security compromise procedures following any suspected repository or credential breach.
- Daily encrypted cloud backups to ensure business continuity and disaster recovery capability.
- Clearly defined customer administrative responsibilities, including timely notification whenever privileged system administrators change.
Encrypted daily backups provide resilience against server failure, hardware faults, fire, natural disasters and other catastrophic events. Where recovery is required, the most recent verified backup is used to restore customer systems and minimise operational disruption.
Identity and Access Management
Fobisoft Solutions Ltd. implements Identity and Access Management (IAM) controls to ensure that only authenticated and authorised individuals are granted access to information systems, software platforms and information assets. Access permissions are assigned strictly according to business responsibilities and the principle of least privilege.
Customer user accounts and security privileges within Hospitum, FobiPoS and other licensed platforms are administered exclusively by authorised Client System Administrators. Access rights are reviewed periodically and must be updated promptly whenever personnel roles, responsibilities or employment status change.
- Access is granted according to the principle of least privilege, ensuring users receive only the permissions necessary to perform their assigned duties.
- Customer user accounts, password resets, role assignments and privilege management are the responsibility of authorised Client System Administrators.
- Administrative and privileged accounts shall be restricted to authorised personnel with legitimate operational requirements.
- Access to Fobisoft corporate systems is permitted only from trusted company-approved devices using approved authentication mechanisms.
- User accounts belonging to employees, contractors or customer personnel shall be disabled or removed immediately upon termination of employment, contract completion or role change.
User authentication establishes identity, while authorisation determines the resources and functions available to each user. Fobisoft maintains strict separation of these controls to reduce security risk, protect sensitive information and maintain accountability across all supported systems.
Cryptographic Controls
Fobisoft Solutions Ltd. employs industry-recognised cryptographic controls to safeguard the confidentiality, integrity and authenticity of information throughout its lifecycle. Cryptographic mechanisms are implemented to protect sensitive information against unauthorised disclosure, interception and tampering during storage, transmission and processing.
The organisation continuously reviews cryptographic technologies to ensure alignment with current industry recommendations and evolving security threats. Encryption standards are applied consistently across software platforms, cloud services, backup infrastructure and customer communications wherever sensitive information is processed.
- Transport Layer Security (TLS) is used to protect information transmitted across public and private networks.
- All public-facing APIs and web services are exposed exclusively through secure HTTPS endpoints.
- User passwords are never stored in plain text and are protected using secure one-way cryptographic hashing algorithms.
- Customer backup archives are encrypted using strong encryption standards such as Advanced Encryption Standard (AES) prior to storage within cloud backup infrastructure.
- Cryptographic keys, certificates and related secrets are managed using controlled access procedures and are protected against unauthorised disclosure.
Cryptographic controls form a foundational component of Fobisoft's security architecture by protecting sensitive information both while in transit and at rest. These controls support regulatory compliance, preserve customer trust and reduce the risk of information compromise resulting from interception or unauthorised access.
Secure Software Development Lifecycle
Fobisoft Solutions Ltd. integrates information security throughout the Software Development Lifecycle (SDLC) for all software products, including Hospitum, FobiPoS, DauLabs and all Artificial Intelligence initiatives. Security is considered from project inception through deployment and ongoing maintenance to ensure that software is resilient against security threats while meeting business and regulatory requirements.
Every software release follows a structured development methodology that incorporates technical reviews, quality assurance and security validation before deployment into production environments. Security is treated as a continuous engineering activity rather than a final-stage verification exercise.
| Phase | Purpose |
|---|---|
| Requirements | Define business, functional, regulatory and security requirements. |
| Design | Create secure architecture, technical designs and data protection controls. |
| Development | Develop software using secure coding practices and approved technologies. |
| Testing | Verify functional correctness, quality and business requirements. |
| Review | Conduct peer reviews and management validation before release. |
| Security Testing | Assess the application for vulnerabilities and validate implemented security controls. |
| Approval | Obtain formal management approval prior to production deployment. |
| Deployment | Release approved software using controlled deployment procedures. |
| Maintenance | Provide updates, security patches, monitoring and continual improvement. |
Security Testing, formal Management Approval and Deployment Authorisation are mandatory controls for every production release. These activities shall not be omitted or bypassed prior to software deployment into customer production environments.
Lessons learned from customer feedback, operational support, vulnerability assessments and emerging cybersecurity threats are incorporated into future development cycles to continuously improve the security, reliability and resilience of Fobisoft software products.
Customer Data Stewardship
Fobisoft Solutions Ltd. acts as a trusted steward of customer information entrusted to the organisation during software implementation, technical support, maintenance and disaster recovery operations. Customer information is processed only for legitimate, authorised business purposes and in accordance with contractual, legal and regulatory obligations.
Customer information remains the property of the respective customer. Fobisoft processes such information solely to deliver agreed services, maintain software reliability, resolve technical issues and support secure business operations. Every employee, contractor and authorised representative is expected to handle customer information with the highest level of confidentiality and professional responsibility.
- Customer information shall be processed only for authorised implementation, technical support, software maintenance, disaster recovery and other contractually agreed activities.
- Employees, developers, support personnel and contractors shall never access, disclose or use customer information for personal benefit or any unauthorised purpose.
- Access to customer information shall be limited to personnel with a legitimate business requirement and appropriate authorisation.
- Customer databases used during authorised troubleshooting, testing or support activities shall be securely removed from development and testing environments immediately after the authorised work has been completed.
- Customer information shall be protected throughout its lifecycle using appropriate administrative, technical and organisational safeguards.
Customer information shall not be used for marketing, Artificial Intelligence model training, product demonstrations, research activities or unrelated software testing unless explicit customer authorisation has been obtained or another lawful basis for processing exists under applicable data protection legislation.
Fobisoft recognises that trust is fundamental to every customer relationship. The organisation is committed to maintaining the confidentiality, integrity and availability of customer information while ensuring that all processing activities remain transparent, proportionate and consistent with contractual obligations and applicable privacy laws.
Remote Working Requirements
Fobisoft Solutions Ltd. supports remote working while maintaining the same level of information security expected within company-controlled environments. Employees, contractors and authorised personnel working remotely shall protect company and customer information by complying with approved security controls and operational procedures.
Remote access to company resources shall be permitted only from trusted devices using secure internet connectivity and company-approved Virtual Private Network (VPN) services. All remote users are responsible for ensuring that their working environment prevents unauthorised access to confidential information.
- Company information shall only be accessed from trusted, company-approved devices.
- Remote connections shall utilise secure internet connectivity together with approved VPN services whenever accessing company systems or customer environments.
- Accessing company resources from public or shared computers is strictly prohibited.
- Automatic screen locking shall be enabled on all authorised devices to protect unattended workstations.
- Individual user accounts shall be used at all times. Shared accounts and credential sharing are prohibited.
- Confidential information shall not be exposed where it may be viewed or overheard by unauthorised persons.
Remote working shall not reduce the security posture of the organisation. Personnel are expected to maintain the same level of confidentiality, integrity and accountability when working remotely as when operating from company premises or customer facilities.
Every authorised remote worker is personally responsible for safeguarding company devices, protecting authentication credentials, maintaining secure working environments and reporting any suspected security incident immediately through the established incident reporting procedures.
Endpoint Security
Fobisoft Solutions Ltd. protects endpoint devices against unauthorised access, malware, data loss and other cybersecurity threats by implementing security controls appropriate to the organisation's operational environment. All company-managed devices accessing corporate or customer information shall comply with approved endpoint security requirements.
Endpoint security applies to desktops, laptops, development virtual machines and other authorised computing devices used by employees and contractors when performing company business. Devices failing to meet minimum security requirements may be denied access to company systems until compliance has been restored.
- Company-managed devices shall implement full-disk encryption to protect information stored locally.
- Operating systems and installed software shall be kept up to date through the timely installation of security patches and vendor updates.
- Approved anti-malware and endpoint protection software shall be installed, enabled and maintained on all supported devices.
- Devices shall be protected using secure authentication, automatic screen locking and strong user passwords.
- Only authorised software and approved security tools may be installed on company-managed devices.
Devices that do not comply with the organisation's endpoint security requirements shall not be used to access company systems, customer environments or confidential information until all identified security deficiencies have been addressed.
Endpoint security provides the first line of defence against malware, ransomware, credential theft and unauthorised access, helping to protect both company assets and customer information throughout their lifecycle.
Backup and Disaster Recovery
Fobisoft Solutions Ltd. maintains backup and disaster recovery capabilities to ensure the continued availability of business operations and customer information following equipment failure, cyber incidents, natural disasters or other disruptive events. Backup processes are designed to support timely restoration while protecting the confidentiality and integrity of backed-up data.
Customer database backups are generated in accordance with company backup procedures and securely transmitted to approved cloud infrastructure where they are encrypted and retained in accordance with the applicable Data Retention and Disposal Policy. Backup operations are continuously monitored to verify successful completion and identify operational failures requiring investigation.
- Customer backup archives shall be encrypted before being stored within approved backup infrastructure.
- Backup operations shall be monitored to verify successful completion and identify failures requiring corrective action.
- Backup retention shall comply with approved company retention and disposal requirements.
- Restoration procedures shall be documented and maintained to support timely recovery following system failure or disaster.
- Access to backup archives shall be restricted to authorised personnel with legitimate operational responsibilities.
Disaster recovery testing shall be conducted at least twice each calendar year to verify that backup archives remain recoverable, restoration procedures are effective and business continuity objectives can be achieved within acceptable operational timeframes.
Backup and disaster recovery capabilities form a critical component of Fobisoft's business resilience strategy, enabling rapid recovery from operational disruptions while minimising the impact on customers, business operations and information assets.
Third-Party and Contractor Management
Fobisoft Solutions Ltd. recognises that third-party service providers, consultants and contractors may require access to company or customer information while performing authorised business activities. Such access shall be carefully managed to ensure that security, confidentiality and privacy obligations remain equivalent to those expected of company personnel.
Access granted to external parties shall be limited to the minimum privileges necessary for the authorised assignment and shall remain valid only for the duration of the approved engagement. Upon completion or termination of the engagement, all associated system access and credentials shall be revoked without unnecessary delay.
- Confidentiality Agreements shall be executed before access to company or customer information is granted.
- Non-Disclosure Agreements (NDAs) shall be completed where access to confidential information or intellectual property is required.
- Contractors and third parties shall acknowledge and comply with the Company's Acceptable Use Policy before receiving system access.
- Access permissions shall be restricted according to the principle of least privilege and limited to authorised contractual activities.
- Temporary accounts, repository permissions, VPN access and other authorised privileges shall be removed immediately upon contract completion or termination.
All third parties are expected to maintain security standards equivalent to those required of Fobisoft personnel. Failure to comply with contractual security obligations may result in immediate termination of access, contract suspension or other appropriate legal and administrative action.
Fobisoft periodically reviews third-party relationships to ensure continued compliance with contractual obligations, security expectations and applicable legal and regulatory requirements. Security responsibilities extend throughout the entire supplier and contractor lifecycle.
Security Awareness and Training
Fobisoft Solutions Ltd. recognises that informed personnel are one of the organisation's strongest security controls. Continuous security awareness helps reduce the likelihood of human error, social engineering attacks and accidental disclosure of sensitive information. Every authorised user is expected to understand and actively support the organisation's information security objectives.
Security awareness is an ongoing process rather than a one-time activity. Employees, contractors and other authorised users shall receive periodic training appropriate to their roles to ensure they remain aware of evolving cybersecurity threats, regulatory obligations and company security procedures.
- Every authorised user shall complete at least two security awareness training sessions during each calendar year.
- Security training shall include topics such as phishing, password security, social engineering, malware awareness, secure remote working and information handling practices.
- New employees and contractors shall receive appropriate security awareness guidance before being granted access to company information systems.
- Personnel are encouraged to report suspected security weaknesses, phishing attempts or other cybersecurity concerns immediately through established reporting channels.
- Training records shall be maintained where appropriate to demonstrate compliance with organisational security requirements.
Effective information security depends upon the awareness, vigilance and responsible actions of every authorised user. Continuous education strengthens the organisation's ability to identify, prevent and respond to cybersecurity threats before they impact business operations or customer information.
Fobisoft periodically reviews its security awareness programme to address emerging threats, technological changes and evolving legal or regulatory requirements, ensuring that training remains current, practical and relevant to the organisation's operational environment.
Regulatory Compliance
Fobisoft Solutions Ltd. is committed to conducting its business in compliance with applicable laws, regulations, contractual obligations and recognised industry best practices. Information security controls shall be implemented and maintained to support compliance while protecting the confidentiality, integrity and availability of company and customer information.
Compliance activities form part of the organisation's governance framework and are supported through documented policies, operational procedures, periodic reviews and continual improvement initiatives. Where legal, contractual or regulatory requirements evolve, Fobisoft shall review and update its security practices to maintain ongoing compliance.
- Comply with applicable legislation and regulatory requirements within the Republic of Kenya.
- Fulfil contractual information security obligations agreed with customers, suppliers and business partners.
- Maintain policies, procedures and operational controls that support legal, regulatory and contractual compliance.
- Periodically review organisational practices to address legislative changes, emerging cybersecurity risks and evolving business requirements.
- Continue improving the Information Security Management Programme while working towards alignment with recognised international standards such as ISO/IEC 27001.
Compliance is viewed as an ongoing organisational responsibility rather than a one-time activity. Fobisoft continually evaluates and strengthens its information security practices to improve resilience, maintain customer confidence and respond effectively to changing legal, technological and business environments.
This Information Security Policy operates together with Fobisoft's supporting governance policies, including the Data Protection Policy, Access Control Policy, Password Policy, Backup Policy and other approved organisational procedures, forming a comprehensive information security governance framework.
Policy Exceptions
Fobisoft Solutions Ltd. recognises that exceptional business or operational circumstances may occasionally require temporary deviations from the requirements of this Information Security Policy. Such exceptions shall be strictly controlled to ensure that any associated information security risks remain understood, documented and appropriately managed.
Policy exceptions shall be considered only where there is a legitimate business justification and where suitable alternative controls can be implemented to minimise any resulting security risks. Exceptions shall never be regarded as permanent changes to this policy.
- Policy exceptions require written approval from the Implementation & Technical Director or a formally delegated representative.
- Every approved exception shall include the business justification, scope, duration and any compensating security controls.
- Approved exceptions shall be reviewed periodically to determine whether they remain necessary.
- Temporary exceptions shall expire automatically unless formally renewed through the approved exception process.
- Records of approved policy exceptions shall be retained for audit and governance purposes.
Information security exceptions are intended to address exceptional operational requirements and shall not compromise the overall security posture of the organisation. Wherever practical, alternative safeguards shall be implemented to reduce any additional risk introduced by the approved exception.
The authority to approve policy exceptions remains the responsibility of the Implementation & Technical Director, or an individual formally authorised to act on their behalf. No employee, contractor or third party may independently waive the requirements of this Information Security Policy.
Enforcement and Disciplinary Actions
Compliance with this Information Security Policy is mandatory for all employees, directors, contractors, consultants and other authorised users who access Fobisoft information systems or customer information. Failure to comply with this policy may expose the organisation and its customers to significant legal, operational and reputational risks.
All suspected policy violations shall be investigated fairly, consistently and in accordance with applicable employment, contractual and legal requirements. Corrective actions shall be proportionate to the nature, severity and impact of the violation, while taking into account whether the incident resulted from negligence, intentional misconduct or criminal activity.
- Security counselling and corrective guidance.
- Formal verbal or written warnings.
- Temporary or permanent suspension of system access privileges.
- Disciplinary action in accordance with employment or contractual obligations.
- Termination of employment or contractual engagement.
- Civil legal proceedings where appropriate.
- Referral to law enforcement authorities where criminal activity is suspected.
Enforcement actions shall always be proportionate to the severity of the policy violation, the associated information security risk and the potential impact on customers, information assets and business operations.
Every authorised user has a responsibility to report known or suspected violations of this policy immediately through the organisation's established incident reporting procedures. Reports made in good faith shall be treated professionally and investigated in accordance with approved governance processes.
Definitions and Glossary
The following definitions apply to Version 1.0 of this Information Security Policy. Unless otherwise stated, these terms shall be interpreted according to their commonly accepted information security meaning within the Fobisoft Information Security Governance Framework.
| Term | Definition |
|---|---|
| Confidentiality | Ensuring that information is accessible only to authorised individuals, systems or processes. |
| Integrity | Protecting information from unauthorised modification, corruption or destruction while maintaining its accuracy and completeness. |
| Availability | Ensuring that authorised users have reliable and timely access to information, systems and services whenever required. |
| Information Asset | Any information, software, hardware, document, repository, database or other resource that has value to Fobisoft or its customers. |
| Customer Data | Information provided by or collected on behalf of customers during implementation, operation, maintenance or support of Fobisoft products and services. |
| Least Privilege | The security principle whereby users receive only the minimum permissions necessary to perform their authorised responsibilities. |
| Encryption | The process of converting information into a protected format that can only be accessed using authorised cryptographic keys. |
| Backup | A protected copy of information maintained for the purpose of restoring systems or data following accidental loss, corruption or disaster. |
| VPN | A Virtual Private Network that provides a secure, encrypted communication channel between authorised devices and company resources. |
| Incident Response | The coordinated process used to identify, contain, investigate, recover from and learn from information security incidents. |
Where terminology is not explicitly defined within this policy, words and expressions shall be interpreted according to their ordinary information security meaning, applicable legislation and other approved Fobisoft governance documents.
Revision History
This document shall be maintained under the Fobisoft Information Security Governance Framework. All revisions shall be reviewed, approved and recorded to ensure that only the latest authorised version is used throughout the organisation.
| Version | Date | Description | Approved By |
|---|---|---|---|
| 1.0 | 2026 | Initial approved corporate issue of the Information Security Policy. | Board of Directors |
Future revisions shall document the nature of each change, approval authority and effective implementation date to maintain a complete audit trail throughout the policy lifecycle.
Related Policies
This Information Security Policy forms the foundation of the Fobisoft Information Security Governance Framework and shall be read together with supporting governance policies, standards and operational procedures. These documents collectively establish the organisation's security, privacy and compliance requirements.
| Document ID | Governance Document |
|---|---|
| FB-DPP-002 | Data Protection & Privacy Policy |
| FB-ACP-003 | Access Control Policy |
| FB-DCH-004 | Data Classification & Handling Policy |
| FB-PWP-005 | Password Policy |
| FB-IRP-006 | Incident Response Policy |
| FB-BUP-007 | Backup & Disaster Recovery Policy |
| FB-BCP-008 | Business Continuity Policy |
| FB-DRD-010 | Data Retention & Disposal Policy |
| FB-HSW-014 | Hospitum Security & Privacy Whitepaper – Authentication & Identity |
All current and future Fobisoft governance documents shall align with the principles established by this Information Security Policy. Where conflicts arise, the more stringent security requirement shall apply unless otherwise approved through the formal Policy Exception process.