Information Security Policy
Public principles for protecting information, systems and communications relevant to Azari Capital.
Risk-based security
Controls should reflect the sensitivity of information, the importance of the system and the consequences of compromise.
Access control
Access should be limited to authorised people and removed when it is no longer required.
Authentication
Strong authentication should be used for systems handling sensitive or privileged information where supported.
Data handling
Confidential or sensitive information should be stored, transmitted and disposed of using controls appropriate to its classification.
Third parties
Operating knowledge from elsewhere in the Azari group can sharpen diligence, but it does not replace independent underwriting. Any relationship with another Azari company is assessed on its own economics, risks, governance and conflicts.
Vulnerability management
Systems should be maintained, patched and reviewed for known weaknesses based on risk and operational context.
Incident response
Suspected security events should be reported, contained, investigated and documented promptly.
Business continuity
Important systems and records should have recovery arrangements proportionate to their role.
Human factors
Phishing, social engineering and accidental disclosure remain material risks. Security awareness should reflect real working practices.
Public reporting
Suspicious communications or website security concerns can be reported to hello@azaricapital.com without sending unnecessary sensitive data.
