MNES Logo
Compliance

Infrastructure Security Compliance Statement

This document outlines the infrastructure security measures implemented by MN Groups to protect customer data, applications, and IT infrastructure.

Infrastructure Security

Infrastructure security is designed to provide a secure, resilient, and reliable operating environment for business applications and customer data. Enterprise-grade firewall protection, operating system hardening, secure administrative controls, regular security patching, and continuous infrastructure monitoring are implemented to reduce operational and cybersecurity risks. Administrative access is restricted to authorized personnel based on the principle of least privilege, while periodic configuration reviews help ensure alignment with recognized security best practices.

Network Security

Network communications are protected through multiple layers of security designed to prevent unauthorized access and minimize exposure to cyber threats. Enterprise firewall policies, traffic filtering, secure remote administration, DNS protection, and controlled inbound and outbound network access help safeguard business systems and customer information. Continuous monitoring of network devices and services enables early detection of security events and supports timely incident response to maintain service availability.

Identity & Access Management

Access to business systems and customer information is managed through Microsoft Entra ID and Microsoft 365 using Role-Based Access Control (RBAC) and the principle of least privilege. Multi-Factor Authentication (MFA) is enforced using Microsoft Authenticator and mobile number verification to strengthen account security. User access is reviewed periodically, and permissions are promptly updated or revoked when employees change roles or leave the organization, helping ensure that only authorized users have access to corporate resources.

Endpoint Security

Corporate endpoints, including workstations, laptops, and servers, are protected through enterprise endpoint security solutions that provide real-time defense against malware, ransomware, viruses, and other cybersecurity threats. Security policies, automatic signature updates, operating system patch management, and continuous endpoint monitoring help maintain device integrity and reduce exposure to known vulnerabilities. Access to corporate resources is permitted only from authorized and managed devices to ensure a secure computing environment.

Email Security

Business email communications are protected through multiple security controls designed to reduce the risk of phishing, spoofing, malware, and other email-based threats. Industry-standard email authentication technologies, including Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC), are implemented where applicable to validate message authenticity. Anti-spam, anti-phishing, and malware filtering mechanisms further enhance email security by helping prevent unauthorized or malicious messages from reaching users.

Data Protection & Encryption

Customer and business information is protected through a combination of technical and organizational security controls designed to prevent unauthorized access, modification, disclosure, or loss. Data transmitted across public networks is secured using HTTPS with Transport Layer Security (TLS) 1.2 or higher, while data stored within Microsoft 365 and Microsoft OneDrive benefits from Microsoft's encryption-at-rest mechanisms, including AES-256 encryption. Access to sensitive information is restricted according to business responsibilities, and user permissions are reviewed periodically to ensure appropriate levels of access are maintained.

Backup & Disaster Recovery

Business continuity is supported through a cloud-based backup and recovery strategy that safeguards critical organizational data against accidental loss, hardware failure, or operational disruption. Business documents and essential information are securely synchronized with Microsoft OneDrive, providing version history, secure cloud storage, and recovery capabilities. Backup processes are monitored regularly, and recovery procedures are maintained to facilitate the timely restoration of information and minimize service interruptions during unexpected events.

Secure Source Code Management

Application source code and development assets are managed using GitHub Organization repositories with centralized administration and delegated access controls. Repository permissions are assigned based on employee roles to ensure that only authorized personnel can access or modify source code. Version control, authenticated user access, and comprehensive change tracking support secure software development practices while protecting intellectual property and maintaining the integrity of development activities.

Vulnerability & Patch Management

Security vulnerabilities are managed through a structured process of regular system assessments, software updates, and timely deployment of security patches. Operating systems, applications, and supporting software components are monitored for vendor-released updates, with critical vulnerabilities prioritized according to their potential impact. Unsupported or end-of-life software is upgraded or retired wherever practical to reduce the organization's exposure to known security risks and maintain a secure operating environment.

Infrastructure Monitoring & Alerting

Continuous monitoring of business-critical infrastructure is performed using Zabbix to provide visibility into the health, availability, and performance of servers, network devices, and essential services. System resources including CPU utilization, memory consumption, storage capacity, and network connectivity are monitored around the clock, with automated alerts generated whenever predefined thresholds, service interruptions, or operational anomalies are detected. This proactive approach enables timely investigation, rapid incident response, and improved service reliability.

Linux Server Security

Linux-based servers are secured using industry-standard security controls to protect systems from unauthorized access and cyber threats. Administrative access is permitted only through Secure Shell (SSH) using PEM key-based authentication, eliminating the need for password-based logins wherever applicable. Firewall policies, regular operating system updates, security patch management, and restricted administrative privileges help maintain a secure server environment and reduce the organization's attack surface.

Incident Management

Security incidents are managed through a structured process designed to identify, assess, contain, investigate, and resolve events that may affect the confidentiality, integrity, or availability of business information and services. Infrastructure monitoring and automated alerting enable early detection of operational or security-related issues, while corrective actions are implemented to minimize impact, restore normal operations, and reduce the likelihood of recurrence. Significant incidents are documented and reviewed to support continuous improvement of security practices.

Business Continuity

Business continuity measures are established to support the availability of critical business services during unexpected disruptions. Cloud-based data backups, infrastructure monitoring, recovery procedures, and preventive maintenance activities help reduce operational risks and enable the timely restoration of essential systems and information. Recovery planning is reviewed periodically to improve organizational resilience and support the continuity of business operations.

Employee Security

Access to information systems is granted according to job responsibilities and business requirements through Role-Based Access Control (RBAC). Employees are required to comply with organizational security policies, maintain the confidentiality of business information, and use corporate systems responsibly. User accounts and access privileges are reviewed periodically, while access is modified or revoked promptly following role changes or employment termination to ensure continued protection of organizational assets.

Retention and Erasure of Data

Customer data is retained only for the period necessary to deliver contracted services and to satisfy applicable legal, regulatory, and contractual obligations. Appropriate technical and organizational measures are applied to protect information throughout its lifecycle. Upon termination of services or completion of contractual requirements, customer data is securely removed from production systems in accordance with established data retention procedures. Backup copies are retained only for the applicable backup retention period and are securely deleted upon expiration of the retention cycle. Access to retained information is restricted to authorized personnel, and secure deletion methods are followed to help ensure that data cannot be recovered once permanently erased.

Data Portability

Customer-owned data can be made available upon authorized request in commonly accepted electronic formats, subject to contractual agreements and applicable legal requirements. Appropriate identity verification procedures are completed before any data is released to ensure that information is provided only to authorized individuals. Data exports are performed through secure transfer methods to preserve confidentiality and maintain the integrity of customer information during transmission.

Service Availability

Service availability is supported through continuous infrastructure monitoring, preventive maintenance, regular system updates, and proactive incident management. Critical infrastructure components are monitored around the clock using automated monitoring solutions to identify potential issues before they impact business operations. Planned maintenance activities are scheduled to minimize disruption, and reasonable efforts are made to maintain reliable and consistent service availability. Although every effort is made to ensure uninterrupted operations, temporary service interruptions may occur due to scheduled maintenance, infrastructure upgrades, or circumstances beyond organizational control.

Privacy & GDPR Support

The protection of personal information is supported through appropriate technical and organizational measures designed to meet applicable privacy and data protection requirements. Security controls such as access management, encryption, secure data transmission, cloud-based protection, and continuous monitoring help safeguard personal information against unauthorized access, disclosure, alteration, or loss. Personal data is processed only for legitimate business purposes and handled in accordance with applicable contractual, legal, and regulatory obligations, including the principles of the General Data Protection Regulation (GDPR), where applicable.

Compliance Statement

Information security is an integral part of MN Groups' operational and software development practices. Security controls are continuously reviewed and enhanced to address emerging cybersecurity threats, evolving regulatory requirements, and changing business needs. Industry-recognized security principles, including secure access management, encryption technologies, continuous infrastructure monitoring, secure software development practices, vulnerability management, and data protection controls, are incorporated into daily operations to support a secure and resilient technology environment. Through ongoing improvements and the adoption of established security best practices, MN Groups remains committed to protecting the confidentiality, integrity, and availability of customer information while delivering secure, reliable, and trusted technology solutions.

Let’s Talk

From custom demos to customization - we are here to delight you

USA (HQ)

332 S Michigan Ave Suite 121 # 5695
Chicago, IL 60604.

+1 (269) 625-5034

USA

2412 W Heather Road, Suite 210,
Wilmington, DE 19803.

+1 (269) 625-5034

USA

32C Germay Dr,
Wilmington, DE 19804.

+1 (269) 625-5034

India (HQ)

5th floor, BNT Connections, 126,
Nelson Manickam Rd, Railway Colony,
Aminjikarai, Chennai, Tamil Nadu 600030.

+91 89258 29574

The images of projects displayed on this website are not owned by our company and may be subject to third-party copyrights. We disclaim any liability for copyright infringement related to these images. The data provided on this site is for informational purposes only, based on our internal estimates. This information is not intended to serve as an indication of Key Performance Indicators (KPIs) and is provided "as is" without any warranties, either express or implied, regarding its accuracy, completeness, or reliability.

© 2026 MN Groups. All rights reserved.