Gelmud
Gelmud

Security Policy

Last updated: February 26, 2026

Information Security Commitment

Gelmud is committed to protecting the security and integrity of all information entrusted to us by our users. This Security Policy outlines the measures we implement to safeguard your data and maintain the confidentiality, availability, and integrity of our educational platform.

Data Protection Framework

We employ a comprehensive security framework designed to protect user information from unauthorized access, disclosure, alteration, or destruction. Our approach encompasses technical, administrative, and physical safeguards.

Encryption Standards

All data transmitted between your device and our servers is protected using industry-standard encryption protocols. We utilize Transport Layer Security (TLS) to ensure secure communication channels. Sensitive data stored on our systems is encrypted at rest using advanced encryption algorithms.

Access Controls

Access to user data is restricted to authorized personnel who require such access to perform their job functions. We implement role-based access controls and enforce the principle of least privilege across our systems.

Infrastructure Security

Our platform infrastructure is designed with security as a foundational element.

Network Security

We maintain secure network architecture with multiple layers of protection including:

  • Firewalls configured to restrict unauthorized network traffic
  • Intrusion detection and prevention systems
  • Regular network security assessments and penetration testing
  • Segmented network zones to isolate sensitive systems

Server Security

Our servers are housed in secure data centers with restricted physical access. We implement hardened server configurations, disable unnecessary services, and maintain current security patches across all systems.

Application Security

Security is integrated throughout our software development lifecycle.

Secure Development Practices

Our development team follows secure coding standards and conducts regular code reviews focused on identifying and remediating security vulnerabilities. We perform security testing prior to deploying updates to our production environment.

Vulnerability Management

We maintain an active vulnerability management program that includes:

  • Regular security scanning of our applications and infrastructure
  • Timely application of security patches and updates
  • Monitoring of security advisories relevant to our technology stack
  • Coordinated disclosure process for reported vulnerabilities

Authentication and Authorization

We implement robust authentication mechanisms to verify user identity and control access to platform resources.

Password Security

User passwords are protected using strong cryptographic hashing algorithms with individual salts. We enforce password complexity requirements and encourage users to create unique, strong passwords. Passwords are never stored in plain text or reversible formats.

Multi-Factor Authentication

We support multi-factor authentication options to provide an additional layer of security beyond passwords. Users are encouraged to enable this feature to enhance account protection.

Session Management

User sessions are managed securely with automatic timeout mechanisms. Session identifiers are generated using cryptographically secure methods and transmitted only over encrypted connections.

Data Backup and Recovery

We maintain regular backups of user data to ensure business continuity and data recovery capabilities. Backup data is encrypted and stored in geographically separate locations. We regularly test our recovery procedures to verify their effectiveness.

Monitoring and Incident Response

Our security operations include continuous monitoring of our systems for potential security events.

Security Monitoring

We employ automated monitoring tools to detect suspicious activities, unauthorized access attempts, and potential security incidents. Security logs are collected, analyzed, and retained in accordance with our data retention policies.

Incident Response Procedures

We maintain a formal incident response plan to address security incidents promptly and effectively. Our response procedures include:

  • Immediate containment of identified threats
  • Investigation to determine the scope and impact of incidents
  • Remediation of vulnerabilities that enabled the incident
  • Notification to affected users as required
  • Post-incident review to improve security measures

Third-Party Security

We carefully evaluate the security practices of third-party service providers who process data on our behalf. Our vendor management process includes security assessments and contractual requirements for data protection.

Employee Security

All employees with access to user data undergo background checks and receive security awareness training. Employees are required to acknowledge and comply with our information security policies.

Security Training

We provide regular security training to our staff covering topics such as:

  • Secure handling of sensitive information
  • Recognition of social engineering and phishing attempts
  • Incident reporting procedures
  • Privacy and data protection requirements

Physical Security

Physical access to facilities where user data is stored or processed is controlled through multiple security measures including access badges, surveillance systems, and visitor management protocols.

Payment Security

Payment information is processed through certified payment processors that comply with Payment Card Industry Data Security Standard (PCI DSS) requirements. We do not store complete payment card information on our systems.

User Responsibilities

While we implement comprehensive security measures, users also play a critical role in protecting their accounts and information. Users are responsible for:

  • Maintaining the confidentiality of login credentials
  • Using strong, unique passwords
  • Logging out after completing sessions on shared devices
  • Promptly reporting suspected security incidents or unauthorized access
  • Keeping contact information current for security notifications

Security Vulnerability Reporting

We welcome reports of potential security vulnerabilities from security researchers and users. If you discover a security issue, please report it to us at help@gelmud.com. We request that you:

  • Provide detailed information about the vulnerability
  • Avoid accessing or modifying data that does not belong to you
  • Allow us reasonable time to address the issue before public disclosure

Compliance and Certifications

We maintain compliance with applicable data protection regulations and industry security standards. Our security program is subject to regular internal audits and external assessments.

Security Policy Updates

We review and update our security measures regularly to address evolving threats and incorporate new security technologies. This Security Policy may be revised to reflect changes in our security practices. Material changes will be communicated through our platform or via email.

Limitations

While we implement industry-standard security measures, no system can be completely secure. We cannot guarantee absolute security of information transmitted to or stored on our systems. Users acknowledge that they provide information at their own risk.

Contact Information

For questions or concerns regarding this Security Policy or our security practices, please contact us:

Email: help@gelmud.com
Phone: +380667226622
Address: Victory Ave, 139, Chernihiv, Chernihiv Oblast, Ukraine, 14000