Security Policy
HRHK Solutions, LLC | Effective Date: January 1, 2026 | Last Updated: January 1, 2026
Security Overview
HRHK Solutions approaches security as an engineering discipline, not a product category. Security controls must be designed into architecture from the beginning, not added as an afterthought. The objective is to make compromise harder, detection faster, lateral movement smaller, and recovery more reliable.
We assume systems will be probed and design accordingly. Security decisions are driven by risk assessment and operational reality, not compliance checkboxes alone. This policy describes the security measures HRHK applies to its own infrastructure and recommends for client engagements.
Infrastructure Security
Infrastructure managed or architected by HRHK follows security-conscious design principles:
- Network segmentation where appropriate to limit blast radius
- Firewall policy aligned to actual service requirements, not default configurations
- Logging and monitoring coverage across critical infrastructure components
- Regular patch management with tested deployment procedures
- Configuration hardening based on industry benchmarks and operational requirements
Access Control
Access to HRHK systems and client environments is governed by the principle of least privilege:
- Access granted on a need-to-know basis with appropriate authentication controls
- Multi-factor authentication required for privileged access
- Privileged access logged and periodically reviewed
- Access revoked when engagement concludes or team members no longer require it
- No shared credentials; individual accountability for all access
Encryption
HRHK recommends and implements encryption appropriate to the data being protected:
- Encryption in transit using modern TLS configurations (TLS 1.2+)
- Encryption at rest for sensitive data stored on HRHK-managed systems
- Key management practices that separate key material from encrypted data
- Encryption is one layer within a broader security architecture, not a substitute for other controls
Vulnerability Management
HRHK's approach to vulnerability management encompasses the full lifecycle:
- Discovery through scanning, assessment, and continuous monitoring
- Validation to distinguish exploitable vulnerabilities from theoretical findings
- Prioritization based on actual risk, not just CVSS scores
- Remediation guidance with tested correction procedures
- Verification of corrections and ongoing monitoring for recurrence
Monitoring & Logging
Observability is a security requirement. HRHK implements monitoring and logging practices designed to detect anomalies before they become incidents:
- Centralized log aggregation for critical systems
- Alerting on anomalous patterns, not just threshold breaches
- Log retention aligned to operational and compliance requirements
- Regular review of monitoring coverage and alert effectiveness
Incident Response
The worst time to design an incident plan is during the incident. HRHK maintains incident response procedures that include:
- Defined escalation paths and response roles
- Evidence preservation requirements and procedures
- Communication plans for internal and external stakeholders
- Recovery processes with tested restoration procedures
Backup & Recovery
Backups are not a recovery strategy until recovery has been tested. HRHK's backup philosophy includes:
- Defined RPO (Recovery Point Objective) and RTO (Recovery Time Objective) targets
- Immutable or offsite copies where appropriate for ransomware protection
- Regular recovery testing to validate backup integrity
- A backup that has never been restored is not a backup—it is an assumption
Responsible Disclosure
HRHK maintains a Responsible Disclosure Policy for reporting security vulnerabilities affecting HRHK-controlled systems. We encourage good-faith reporting and commit to responding to legitimate vulnerability reports.
Read our Vulnerability Disclosure PolicySecurity Contact
For security-related inquiries or to report a vulnerability:
- Email: [email protected] (include "Security" in subject line)
- Mailing Address: HRHK Solutions, LLC, P.O. Box 868135, Plano, TX 75086, US