Last updated: 10 July 2026

Security Policy

Security practices for protecting factory operations, employee, payroll, billing and inventory data.

Application Security

Production traffic should be served over HTTPS/TLS.

Passwords are stored using one-way hashing. Factory1 does not store plain text passwords.

Role-based access control is used to limit access by department and responsibility.

Data Protection

Factory1 separates data by organization and restricts users to their assigned organization.

Backups should be maintained at the infrastructure level for production deployments.

Import/export activity and operational events should be logged where supported by the module.

Audit Logs And Monitoring

Factory1 is adding deeper audit logs over time for sensitive business actions such as billing, payroll, accounting and access changes.

Security-relevant activity may be logged for investigation, reliability and abuse prevention.

Vulnerability Reporting

Report suspected vulnerabilities to official.factory.one@gmail.com with steps to reproduce and potential impact.

Please do not access, modify, export or disclose data that does not belong to you while testing.

Incident Response

If Factory1 identifies a material security incident, affected customers will be notified with available details and remediation guidance.

Factory1 will work to contain, investigate and recover from incidents as quickly as reasonably possible.

These pages are written for transparency and onboarding. Commercial agreements, signed DPAs or enterprise contracts may override public policy text where expressly agreed in writing.