Security Policy
Last updated: January 15, 2026 | Effective date: January 15, 2026
At ESMNT, the trading name of TUNGSTEN FOR SOFTWARE AND ARTIFICAL INTELLIGANCE LLC (formerly Mags Group), security is foundational to everything we do. This Security Policy outlines our commitment to protecting our clients' data, our security practices, and the measures we take to ensure the confidentiality, integrity, and availability of information entrusted to us.
1. Our Security Commitment
Security is embedded into our culture, processes, and technology. We are committed to:
- Protecting client data with industry-leading security measures
- Continuously monitoring and improving our security posture
- Maintaining transparency about our security practices
- Complying with applicable laws, regulations, and industry standards
- Promptly addressing security incidents and vulnerabilities
SOC 2 Type II
Compliant
ISO 27001
Compliant
GDPR
Compliant
2. Infrastructure Security
2.1 Cloud Infrastructure
Our infrastructure is hosted on leading cloud platforms that maintain comprehensive security standards:
- Data centers with SOC 2 Type II, ISO 27001, and ISO 27017 compliance
- Physical security including biometric access, 24/7 surveillance, and security personnel
- Redundant power, cooling, and network connectivity
- Geographic distribution for disaster recovery
2.2 Network Security
- Enterprise-grade firewalls and intrusion detection/prevention systems (IDS/IPS)
- Network segmentation to isolate sensitive systems
- DDoS protection and mitigation
- Regular vulnerability scanning and penetration testing
- Encrypted communications using TLS 1.3
2.3 Application Security
- Secure software development lifecycle (SSDLC) with security reviews at each phase
- Static and dynamic application security testing (SAST/DAST)
- Regular third-party security audits and penetration tests
- Dependency scanning and software composition analysis
- Secure coding training for all developers
3. Data Protection
3.1 Encryption
| Data State | Protection Method |
|---|---|
| Data in Transit | TLS 1.3 encryption for all communications |
| Data at Rest | AES-256 encryption for stored data |
| Database | Transparent Data Encryption (TDE) |
| Backups | Encrypted with separate key management |
3.2 Access Control
- Role-based access control (RBAC) with least-privilege principles
- Multi-factor authentication (MFA) required for all system access
- Single sign-on (SSO) integration for enterprise clients
- Regular access reviews and prompt deprovisioning
- Privileged access management for administrative functions
3.3 Data Handling
- Data classification policies to identify and protect sensitive information
- Data loss prevention (DLP) controls
- Secure data disposal procedures
- Data retention policies aligned with legal and contractual requirements
4. Operational Security
4.1 Monitoring & Detection
- 24/7 security operations center (SOC) monitoring
- Security Information and Event Management (SIEM) for log aggregation and analysis
- Automated alerting for security events and anomalies
- User behavior analytics to detect insider threats
4.2 Incident Response
We maintain a comprehensive incident response program that includes:
- Documented incident response procedures and playbooks
- Dedicated incident response team with defined roles
- Regular tabletop exercises and simulations
- Post-incident reviews and lessons learned
- Client notification procedures in accordance with contractual and legal requirements
4.3 Business Continuity
- Business continuity and disaster recovery plans
- Regular backups with tested restoration procedures
- Geographic redundancy for critical systems
- Recovery time objectives (RTO) and recovery point objectives (RPO) defined for each service tier
5. Personnel Security
- Background checks for all employees with access to sensitive systems
- Security awareness training upon hire and annually thereafter
- Phishing simulation exercises
- Acceptable use policies and confidentiality agreements
- Immediate access revocation upon termination
6. Compliance & Standards
ESMNT (formerly Mags Group) maintains compliance with various industry standards and regulations:
SOC 2 Type II
Annual audit covering security, availability, and confidentiality
ISO 27001
Information security management system compliance
GDPR
EU General Data Protection Regulation compliance
HIPAA
Healthcare data protection (for applicable services)
PCI DSS
Payment card industry standards (for applicable services)
Cyber Essentials Plus
UK government-backed standard
7. Third-Party Security
We carefully evaluate the security practices of our vendors and subprocessors:
- Security assessments before onboarding new vendors
- Contractual security requirements and data protection agreements
- Ongoing monitoring of vendor security posture
- Annual vendor security reviews
8. Vulnerability Disclosure
Report a Security Vulnerability
We welcome responsible disclosure of security vulnerabilities. If you believe you have discovered a security issue in any of our products or services, please report it to us.
Email: security@mags-group.com
Please include a detailed description of the vulnerability, steps to reproduce, and any relevant supporting materials. We commit to acknowledging reports within 24 hours and providing updates on remediation progress.
9. Contact Us
For security-related inquiries or to request our security documentation (SOC 2 report, ISO documentation, etc.), please contact:
security@mags-group.com
Information Security Dep.
TUNGSTEN FOR SOFTWARE AND ARTIFICAL INTELLIGANCE LLC (ESMNT, formerly Mags Group).
King Hussain Business Park
Amman, 11953
Hashemite Kingdom of Jordan
