← Security & Trust

Information Security Policy

Fueling Agile Nigeria · AgileFlex / FANMS · Effective 1 January 2026 · Next review 18 January 2027
Owner: David Owolabi · Contact: fuelingagilenigeria@gmail.com

1. Purpose

This policy states how Fueling Agile protects customer, company, and system data for our fleet fuel-management platforms. It is the top-level security policy. More detailed rules live in Access Control, Data Protection, Encryption, Incident Response, Acceptable Use, and Vulnerability Disclosure.

2. Scope

3. Principles

  1. Least privilege — people and systems get only the access they need.
  2. Defence in depth — multiple controls (edge TLS, auth, roles, audit, approvals).
  3. Honesty — we only claim controls that exist in production.
  4. Accountability — sensitive actions are logged and, where required, approved.
  5. Continuous improvement — we review this policy at least every six months, or after a material incident or architecture change.

4. Security objectives

ObjectiveHow we pursue it today
ConfidentialityHTTPS at the edge; secrets kept out of source control; role-based access; company-scoped customer data
IntegrityAuthenticated APIs; approval workflow for high-risk admin changes; audit trails
AvailabilityControlled deploys via CI; production API not exposed directly to the public internet
AccountabilitySession tracking, admin activity logs, correlation IDs

5. Roles and responsibilities

RoleResponsibility
LeadershipApprove this policy; fund security work; accept residual risk
David Owolabi (Security owner)Maintain policies; run reviews; coordinate incidents
Developers & operatorsFollow secure coding and deploy practices; never commit secrets
Platform adminsUse assigned roles only; treat customer data as confidential
CustomersProtect login credentials; report suspected misuse promptly

6. Baseline technical controls

These controls are implemented today and are mandatory for production:

7. What we do not claim yet

Staff must not state these as current product guarantees until implemented and verified:

8. Policy enforcement

Violations may result in access revocation, disciplinary action, and/or contract remedies. Technical enforcement is preferred: authentication, roles, session revocation, approvals, and audit logs.

9. Related policies

Access Control · Data Protection · Encryption · Incident Response · Acceptable Use · Vulnerability Disclosure

10. Review

Version 1.0 — 1 January 2026. Initial public security policy pack aligned to FANMS production controls.