Security Policy

Security Policy

HRHK Solutions, LLC  |  Effective Date: January 1, 2026  |  Last Updated: January 1, 2026

01

Security Overview

HRHK Solutions approaches security as an engineering discipline, not a product category. Security controls must be designed into architecture from the beginning, not added as an afterthought. The objective is to make compromise harder, detection faster, lateral movement smaller, and recovery more reliable.

We assume systems will be probed and design accordingly. Security decisions are driven by risk assessment and operational reality, not compliance checkboxes alone. This policy describes the security measures HRHK applies to its own infrastructure and recommends for client engagements.

02

Infrastructure Security

Infrastructure managed or architected by HRHK follows security-conscious design principles:

  • Network segmentation where appropriate to limit blast radius
  • Firewall policy aligned to actual service requirements, not default configurations
  • Logging and monitoring coverage across critical infrastructure components
  • Regular patch management with tested deployment procedures
  • Configuration hardening based on industry benchmarks and operational requirements
03

Access Control

Access to HRHK systems and client environments is governed by the principle of least privilege:

  • Access granted on a need-to-know basis with appropriate authentication controls
  • Multi-factor authentication required for privileged access
  • Privileged access logged and periodically reviewed
  • Access revoked when engagement concludes or team members no longer require it
  • No shared credentials; individual accountability for all access
04

Encryption

HRHK recommends and implements encryption appropriate to the data being protected:

  • Encryption in transit using modern TLS configurations (TLS 1.2+)
  • Encryption at rest for sensitive data stored on HRHK-managed systems
  • Key management practices that separate key material from encrypted data
  • Encryption is one layer within a broader security architecture, not a substitute for other controls
05

Vulnerability Management

HRHK's approach to vulnerability management encompasses the full lifecycle:

  • Discovery through scanning, assessment, and continuous monitoring
  • Validation to distinguish exploitable vulnerabilities from theoretical findings
  • Prioritization based on actual risk, not just CVSS scores
  • Remediation guidance with tested correction procedures
  • Verification of corrections and ongoing monitoring for recurrence
06

Monitoring & Logging

Observability is a security requirement. HRHK implements monitoring and logging practices designed to detect anomalies before they become incidents:

  • Centralized log aggregation for critical systems
  • Alerting on anomalous patterns, not just threshold breaches
  • Log retention aligned to operational and compliance requirements
  • Regular review of monitoring coverage and alert effectiveness
07

Incident Response

The worst time to design an incident plan is during the incident. HRHK maintains incident response procedures that include:

  • Defined escalation paths and response roles
  • Evidence preservation requirements and procedures
  • Communication plans for internal and external stakeholders
  • Recovery processes with tested restoration procedures
08

Backup & Recovery

Backups are not a recovery strategy until recovery has been tested. HRHK's backup philosophy includes:

  • Defined RPO (Recovery Point Objective) and RTO (Recovery Time Objective) targets
  • Immutable or offsite copies where appropriate for ransomware protection
  • Regular recovery testing to validate backup integrity
  • A backup that has never been restored is not a backup—it is an assumption
09

Responsible Disclosure

HRHK maintains a Responsible Disclosure Policy for reporting security vulnerabilities affecting HRHK-controlled systems. We encourage good-faith reporting and commit to responding to legitimate vulnerability reports.

Read our Vulnerability Disclosure Policy
10

Security Contact

For security-related inquiries or to report a vulnerability:

  • Email: [email protected] (include "Security" in subject line)
  • Mailing Address: HRHK Solutions, LLC, P.O. Box 868135, Plano, TX 75086, US