This Security Policy describes how MMG Entertainment AB (company registration number 559332-8775) protects corporate documents and other business-critical information processed within the service
www.strictboard.com (the “Service”). The objective is to ensure confidentiality, integrity, availability, and traceability in accordance with good industry practice for SaaS services directed at businesses.
1. Scope
This policy covers:
- Documents and files uploaded to the Service
- Metadata associated with documents
- User accounts and access
- System infrastructure and operating environment
2. Information classification
All information stored in the Service is considered confidential corporate information.
The information is protected according to the principle of “security by default”.
Examples include board documents, agreements, strategic documents, financial reports, and internal decision materials.
3. Technical security measures
- All data transmission takes place via TLS (HTTPS)
- Documents are stored encrypted
- Encryption keys are managed separately from stored data
- Role-based access control (RBAC)
- Individual user accounts
- Strong password requirements
- Support for two-factor authentication (2FA)
- Automatic logout after inactivity
- Logging of logins, document access, and administrative changes
4. Infrastructure and operations
- Hosting in a professional data center environment
- Firewalls and network segmentation
- Regular security updates
- Intrusion detection where applicable
- Regular backups stored separately
- Periodically tested restoration procedures
5. Organizational security measures
- Restricted access to the production environment
- Access is documented and reviewed regularly
- Confidentiality agreements for employees and consultants
- Code review and version control
- Separate test and production environments
6. Handling of corporate documents
Corporate documents are stored encrypted and are only accessible to authorized users.
The customer controls which users and roles have access and whether documents may be downloaded.
Customer data is logically separated from other customers’ data.
7. Incident management
MMG has procedures for identification, escalation, mitigation, documentation, and communication in the event of security incidents.
Incidents are handled promptly in accordance with established procedures.
8. Business continuity planning
We maintain backup strategies, recovery plans, operational monitoring, and risk assessments of critical components.
The objective is to minimize service disruption and data loss.
9. Third-party providers
If third-party providers are used, MMG ensures that they meet reasonable security requirements.
Agreements regulate security responsibilities and risk assessments are conducted when necessary.
10. Customer responsibility
- Secure handling of login credentials
- Granting access only to authorized users
- Secure handling of exported materials
- Compliance with internal security policies
11. Revision and updates
This Security Policy is reviewed regularly and updated as necessary to address evolving threats, technical changes, legal requirements, and business development.