Eylorin Technologies

Trust & security

Security built into the foundation.

Eylorin applies security, privacy, resilience, and responsible engineering throughout the lifecycle of its digital products and enterprise systems.

Security by design

Global principles.
Practical controls.

Security is treated as a continuous operating discipline—from concept and architecture through development, deployment, monitoring, incident response, and recovery.

Controls are selected according to system risk, data sensitivity, user needs, regulatory obligations, and the operating environment. Eylorin does not present framework alignment as certification unless an independent certification has been completed and verified.

Control foundations

01

Secure architecture

Least privilege, defence in depth, environment separation, secure defaults, and threat-informed design.

02

Identity & access

Strong authentication, role-based access, privileged-access control, session protection, and periodic access review.

03

Data protection

Data minimisation, encryption in transit and at rest where applicable, retention controls, secure deletion, and protected backups.

04

Secure development

Peer review, automated testing, secret management, dependency scanning, vulnerability remediation, and controlled releases.

05

Monitoring & response

Security logging, anomaly detection, escalation paths, incident containment, investigation, notification, and lessons learned.

06

Resilience & recovery

Availability engineering, tested backups, recovery planning, continuity measures, and supplier-risk management.

Framework alignment

Recognised standards,
applied by risk.

These references guide governance and control selection. Applicability and assurance depth depend on each product, jurisdiction, data type, and deployment.

01

ISO/IEC 27001 & 27002

Information-security governance, risk treatment, access control, supplier assurance, incident management, and continual improvement.

02

NIST Cybersecurity Framework 2.0

Govern, identify, protect, detect, respond, and recover as one connected security lifecycle.

03

CIS Controls & Benchmarks

Secure configuration, asset visibility, vulnerability management, logging, recovery, and practical defensive controls.

04

OWASP ASVS, SAMM & Top 10

Secure design and development, threat modelling, code review, dependency controls, testing, and protection against common application risks.

05

Privacy & sector requirements

Data-minimisation and privacy-by-design principles informed by Uganda’s Data Protection and Privacy Act, GDPR/UK GDPR, and applicable sector rules.

06

Product-specific assurance

PCI DSS, payment-system requirements, healthcare privacy and security duties, and capital-markets controls are applied where a product’s scope makes them relevant.

Responsible reporting

Report a security concern.

If you believe you have identified a security issue affecting an Eylorin website, product, or service, please report it responsibly. Include the affected service, steps to reproduce, potential impact, and a safe way to contact you. Do not access, alter, retain, or disclose data that is not yours.

legal-compliance@eylorin.com