Summary
BeeTcore moves data only over encrypted channels, whether it is traffic to a platform, files to a server, backups to storage, or credentials between team members. Unencrypted methods are never used. Sensitive data is kept to a minimum and encrypted before transfer where required. Transfers across borders follow the data protection laws that apply, and automated transfers are checked, logged, and alerted on if they fail.
1. Principle
Data moves only over encrypted, authenticated channels. Plain FTP, unencrypted web traffic, and sending credentials by email or chat are never used. This document sits within the Cloud Security Framework.
2. Approved methods
- Web traffic and APIs: HTTPS, protected by TLS encryption.
- Files to and from servers: SFTP or SSH, with individual, authenticated accounts.
- Deployments: over SSH or through authenticated pipelines from version control, as set out in the Change Management Framework.
- Backups: to independent storage over encrypted connections, as set out in the Backup and Recovery Standards.
- Migrations between hosts: server-to-server transfers over encrypted connections.
- Email: platform and transactional email is sent over TLS-encrypted connections and authenticated with SPF, DKIM, and DMARC to prevent spoofing.
- Credentials: shared only through the approved team password manager, never by email, chat, or documents, as set out in the Strategic Information Security Awareness Program.
- Client files and assets: exchanged through secure, access-controlled shared storage, with access removed once it is no longer needed.
3. Sensitive data
- Only the data a task needs is exported or transferred.
- Sensitive files are encrypted before transfer where their sensitivity or the client requires it, for example with PGP or GPG encryption.
- Temporary copies are deleted once the task is complete.
4. Cross-border transfers
Where personal data moves between countries, the transfer follows the data protection laws that apply, such as the safeguards the GDPR requires for transfers outside the EU and UK, and the cross-border provisions of the Nigeria Data Protection Act 2023. Where data is stored is set out in the Cloud Security Framework.
5. Validation and error handling
- Verification: transfers such as backups and migrations are checked on completion to confirm they are complete and intact.
- Automated alerts: failed automated transfers, including backups, synchronisations, and integrations, raise alerts to the responsible technical owner.
- Logging: transfer activity and errors are logged where the platform supports it.
- Resolution: common failures are retried automatically where it is safe to do so. Persistent or serious failures are escalated under the Incident Management Response Strategy.
6. Access control
Only authorised team members can transfer data to or from client systems, each through their own account. Access keys and credentials are unique, carry only the permissions they need, and are removed when no longer required.
7. Review and improvement
Transfer failures are analysed for their root cause, and procedures are improved through Continuous Service Improvement. This document is reviewed annually and whenever transfer methods change.
Frequently asked questions
How does BeeTcore transfer data securely?
Only over encrypted channels: HTTPS for web traffic and APIs, SFTP or SSH for files, and encrypted connections for backups and migrations. Unencrypted methods such as plain FTP are never used.
How are passwords and credentials shared?
Only through an approved team password manager, never by email, chat, or documents.
What about transferring personal data between countries?
Cross-border transfers follow the data protection laws that apply, such as the GDPR's safeguards for transfers outside the EU and UK, and the cross-border provisions of the Nigeria Data Protection Act 2023.