Protecting your data and our systems to the highest security standards
Effective Date: February 2026 | Scope: Employees, partners, and all system users
AutoCycle ("we," "us," "our," or "Company") is committed to maintaining the highest standards of security and protecting the confidentiality, integrity, and availability of all information systems and data. This Security Policy outlines our comprehensive approach to information security, covering both customer-facing practices and internal security procedures.
🔒 Encryption in Transit
🛡️ Encryption at Rest
💳 Payment Data Encryption
| Password Requirements | Minimum 12 characters, mix of uppercase, lowercase, numbers, symbols |
| Password Expiration | Every 90 days |
| Password History | System prevents reuse of last 5 passwords |
| Account Lockout | Locked after 5 failed attempts for 30 minutes |
| Session Timeout | 30 minutes of inactivity |
| Concurrent Sessions | Maximum 3 concurrent sessions |
| Session Invalidation | Upon logout or password change |
| Secure Cookies | Marked as secure and httponly |
🔥 Firewall Protection
🔎 Intrusion Detection & Prevention (IDS/IPS)
🛡️ DDoS Protection
🔐 VPN & Secure Remote Access
🦠 Antivirus & Malware Protection
💻 Device Hardening
📱 Mobile Device Security
Marketing materials, public documentation — freely shareable
Policies, procedures, internal communications — internal use only
Financial data, strategic plans, customer lists
Personal data, payment data, credentials — strict controls required
| Backup Frequency | Daily for all critical systems and data |
| Backup Encryption | All backups encrypted with strong algorithms |
| Backup Storage | Geographically diverse locations |
| Backup Testing | Monthly restore tests |
| Recovery Time Objective (RTO) | Critical systems recovered within 4 hours |
| Recovery Point Objective (RPO) | Data loss limited to maximum 1 hour |
📋 Regular Security Audits
🔍 Vulnerability Scanning
⚔️ Penetration Testing
✅ Security Compliance Assessment
Detection & Reporting
Containment & Isolation
Investigation & Analysis
Post-Incident Activities
🚪 Facility Access Control
📹 Surveillance & Monitoring
🖥️ Server Room Security
Business Continuity Plan
Disaster Recovery Plan
Egyptian Regulations
Data protection & privacy laws
PCI DSS
Payment Card Industry Standard
ISO 27001
Information Security Management
Industry Standards
Applicable best practices
🚨 Incident Reporting
📧 incidents@autocycle.com.eg
📞 Security Hotline: +201551911115
🕐 24/7 Security Operations Center
🔐 Vulnerability Disclosure & Security Contact
📧 CISO: ciso@autocycle.com.eg
📧 Security Team: security@autocycle.com.eg
Mark subject as "Security Vulnerability"