Web design fundamentals — taught clearly, learned anywhere in Ukraine
Pesk Wadrun
Pesk Wadrun

Security Policy

Last updated: July 28, 2025

Pesk Wadrun is committed to protecting the security of our platform, our users, and the data entrusted to us. This Security Policy describes the measures we take to safeguard information, the responsibilities of users, and how we respond to security incidents. By using our services at peskwadrun.com, you acknowledge and agree to the practices described in this document.


1. Scope

This policy applies to all systems, infrastructure, and services operated by Pesk Wadrun, including our website, online learning platform, user accounts, and any associated applications. It covers all data processed, stored, or transmitted through our services, as well as the conduct of users and staff who interact with those systems.


2. Data Protection Principles

We apply the following core principles when handling user data and platform resources:


3. Infrastructure Security

3.1 Network and Hosting

Our platform is hosted on infrastructure that employs industry-standard security controls. Network traffic is segmented and monitored. Firewalls and access control lists restrict inbound and outbound connections to only those required for legitimate service operation.

3.2 Encryption in Transit

All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS). We enforce the use of current, supported TLS versions and disable deprecated or insecure cipher suites. Connections over unencrypted protocols are redirected to encrypted equivalents.

3.3 Encryption at Rest

Sensitive data stored within our systems, including user credentials and personal information, is encrypted at rest using accepted cryptographic standards. Encryption keys are managed separately from the data they protect and are rotated on a defined schedule.

3.4 System Hardening

Servers and services are configured according to hardening guidelines. Unnecessary services, ports, and software components are disabled or removed. Operating systems and third-party dependencies are kept up to date with security patches applied in a timely manner.


4. Access Control

4.1 Principle of Least Privilege

Access to systems, databases, and administrative tools is granted on a need-to-know basis. Users and internal staff receive only the minimum level of access required to perform their intended functions. Access rights are reviewed periodically and revoked when no longer necessary.

4.2 Authentication Requirements

Administrative and privileged accounts require strong authentication, including multi-factor authentication where technically feasible. Shared credentials are not permitted for sensitive systems. Session tokens are issued with defined expiration periods and invalidated upon logout or detected anomalies.

4.3 User Account Security

User accounts are protected by password requirements that enforce minimum length and complexity. Passwords are stored using one-way cryptographic hashing with salting. Users are encouraged to choose unique passwords and to avoid reusing credentials across services.


5. Application Security

5.1 Secure Development Practices

Security considerations are incorporated throughout our development lifecycle. Code is reviewed for common vulnerabilities before deployment. We follow established guidelines for secure coding to mitigate risks including injection attacks, cross-site scripting, cross-site request forgery, and insecure direct object references.

5.2 Input Validation and Output Encoding

All user-supplied input is validated and sanitized before processing. Output rendered in the browser is encoded appropriately to prevent script injection. File uploads are restricted by type and size and are scanned before being stored or served.

5.3 Dependency Management

Third-party libraries and components used in our platform are tracked and monitored for known vulnerabilities. Affected dependencies are updated or replaced promptly when security advisories are issued.


6. Monitoring and Logging

Our systems maintain logs of authentication events, administrative actions, and significant application activity. Logs are stored securely and retained for a defined period sufficient to support incident investigation. Automated monitoring is in place to detect unusual patterns, repeated failures, or indicators of unauthorized access. Alerts are reviewed by responsible personnel on a regular basis.


7. Incident Response

7.1 Detection and Containment

When a potential security incident is identified, we act promptly to assess its nature and scope. Affected systems or accounts may be isolated or suspended to prevent further impact while an investigation is conducted.

7.2 Investigation and Remediation

Confirmed incidents are investigated to determine root cause, affected data, and the extent of any unauthorized access or disclosure. Vulnerabilities that contributed to the incident are remediated before affected systems are returned to normal operation.

7.3 Notification

Where an incident results in unauthorized access to user data, affected users will be notified in a timely manner through available contact channels. Notifications will describe the nature of the incident, the type of data involved, and the steps being taken in response. We will also fulfill any applicable notification obligations to relevant authorities.


8. User Responsibilities

Users of our platform share responsibility for maintaining the security of their accounts and interactions. You are expected to:

Failure to observe these responsibilities may result in account suspension or termination.


9. Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities discovered in our platform. If you believe you have identified a security issue, please contact us at support@peskwadrun.com with a clear description of the issue, steps to reproduce it, and any relevant supporting information. We ask that you refrain from publicly disclosing the issue until we have had a reasonable opportunity to investigate and address it. We will acknowledge receipt of valid reports and keep you informed of our progress.


10. Third-Party Services

Our platform may integrate with or rely upon third-party services for functions such as payment processing, analytics, or content delivery. These services are selected with attention to their own security practices. However, we do not control third-party systems and are not responsible for their security posture. Users are encouraged to review the security and privacy policies of any third-party services they interact with through our platform.


11. Business Continuity and Backups

Critical data and configurations are backed up on a regular schedule. Backups are stored securely and tested periodically to verify that restoration is possible. In the event of a significant service disruption, we maintain procedures to restore operations within a defined recovery timeframe.


12. Physical Security

Our services operate within data center environments that maintain physical access controls, including restricted entry, surveillance, and environmental protections such as fire suppression and climate control. Physical access to server infrastructure is limited to authorized personnel of the relevant facility operators.


13. Policy Review and Updates

This Security Policy is reviewed periodically and updated to reflect changes in our practices, technology, or applicable requirements. When material changes are made, the updated policy will be published on this page with a revised effective date. Continued use of our services following the publication of changes constitutes acceptance of the updated policy.


14. Contact

If you have questions about this Security Policy or wish to report a security concern, please contact us: