← Back to Main Page

Security Policy

Supra eKEY Systems Effective Date: January 1, 2026 Last Updated: August 20, 2026

Security is foundational to everything we do at Supra eKEY Systems. This policy describes our security practices, the controls we apply to protect your data and property access, and how to report security vulnerabilities responsibly.

AES-256 Encryption
All stored data is encrypted using AES-256-GCM with per-record keys.
TLS 1.3 in Transit
All network communications use TLS 1.3 with forward secrecy. Downgrade attacks are blocked.
Real-time Monitoring
24/7 intrusion detection, anomaly detection, and automated alerting for all access events.
Zero-Trust Access
Every access request is verified independently. No implicit trust is granted based on network location.

1. Encryption

Data at Rest

Data in Transit

Credential Hashing

2. Access Controls

3. Infrastructure Security

4. Monitoring and Logging

5. Application Security

6. Security Testing

7. Incident Response

We maintain a comprehensive Incident Response Plan (IRP) that includes:

Responsible Vulnerability Disclosure

We welcome reports from security researchers. If you discover a potential security vulnerability in our systems, please report it to us privately before public disclosure so we can address it promptly.

Report to: [email protected]

Our commitment to researchers:

Please do not access or modify data belonging to other users, perform denial-of-service attacks, or test on production systems without prior written authorization.

8. Employee Security

9. Compliance

Our security program is designed to meet or exceed requirements of:

Security Team Contact

Supra eKEY Systems — Security Team
Security issues: [email protected]
General inquiries: [email protected]
Response time for security reports: within 48 hours.