top of page

Rare360 Information Security Policy

Document Owner: Data Protection & Information Security Manager

Approved By: Rare360 Executive Management

Effective Date: January 1, 2026

Review Cycle: Annually or upon material changes to the business or technology environment

Version: 1.0
 

1. Purpose

Rare360 is committed to protecting the confidentiality, integrity, and availability of the information entrusted to us by research participants, caregivers, clients, employees, and business partners.
 

This Information Security Policy establishes the administrative, technical, and organizational safeguards implemented to protect information assets and reduce the risk of unauthorized access, disclosure, alteration, destruction, or interruption.
 

2. Scope

This policy applies to:

  • All Rare360 personnel

  • Contractors and temporary workers

  • Consultants

  • Third-party service providers with access to Rare360 information

  • All systems processing Rare360 information

  • Cloud-based applications

  • Mobile devices authorized for business use
     

3. Information Security Principles

Rare360's security program is based upon the following principles:

  • Least privilege

  • Need-to-know access

  • Defense in depth

  • Data minimization

  • Privacy by Design

  • Secure cloud-first architecture

  • Continuous improvement

  • Risk-based security management
     

4. Information Classification

Information shall be classified as:

Public: Information approved for public release.

Internal: Routine business information not intended for public disclosure.

Confidential: Client information, contracts, internal business records, financial information.

Restricted: Personally identifiable information (PII), protected health information (PHI) where applicable, participant contact information, authentication credentials, and other highly sensitive information requiring the highest level of protection.
 

5. Access Control

Access to information shall be granted only:

  • for legitimate business purposes;

  • using the principle of least privilege;

  • based upon job responsibilities.


Access shall be reviewed periodically.


Accounts shall be disabled promptly following termination of employment or business need.


Shared user accounts are prohibited except where technically unavoidable and formally approved.
 

6. Authentication

Rare360 requires strong authentication controls.
 

Requirements include:

  • Unique user IDs

  • Strong passwords or passphrases

  • Multi-factor authentication where supported for systems containing confidential information

  • Automatic session timeouts

  • Automatic screen locking

  • Protection against repeated failed login attempts


Passwords shall never be shared.
 

7. Encryption

Data at Rest

Sensitive information shall be protected using industry-standard encryption (AES-256 or equivalent) where supported.


This includes:

  • Cloud storage

  • Databases

  • Backups

  • Mobile devices


Data in Transit

Sensitive information shall be encrypted using:

  • TLS 1.2 or higher

  • HTTPS

  • Secure APIs

  • Secure file transfer protocols


Transmission of confidential information over unsecured channels is prohibited.
 

8. Endpoint Security

Company-managed systems shall utilize:

  • Endpoint anti-malware protection

  • Automatic security updates

  • Operating system patching

  • Device authentication

  • Screen lock

  • Encryption where supported

Unauthorized software installation is prohibited.
 

9. Mobile Device Security

Rare360 authorizes limited business use of a secure Android mobile device for respondent communications.


Requirements include:

  • Full-device encryption

  • Strong PIN/password

  • Biometric authentication where enabled

  • Automatic screen lock

  • Current Android security updates

  • Authorized users only


Only the minimum information necessary should be accessed or stored on the device.


Lost or stolen devices shall be reported immediately.
 

10. Vulnerability & Patch Management

Rare360 follows a risk-based patch management process.
 

Critical security updates shall be prioritized.


Cloud service providers are responsible for maintaining the security of the underlying infrastructure.


Rare360 remains responsible for:

  • customer-managed configurations;

  • application settings;

  • account security;

  • timely software updates under its control.
     

11. Malware Protection

Endpoint protection shall provide:

  • Real-time protection

  • Automatic signature updates

  • Malware scanning

  • Quarantine capabilities where supported


Suspected malware incidents shall be reported immediately.
 

12. Incident Response

Rare360 maintains an incident response process consisting of:

  1. Identification

  2. Assessment

  3. Containment

  4. Investigation

  5. Eradication

  6. Recovery

  7. Post-incident review


Incidents involving personal information shall be managed in accordance with applicable legal, contractual, and regulatory obligations.
 

13. Data Retention & Destruction

Personal information shall be retained only as long as necessary to:

  • fulfill business purposes;

  • satisfy contractual obligations;

  • comply with legal requirements.


Upon expiration of retention periods, information shall be securely deleted, anonymized, or otherwise destroyed.
 

14. Respondent Privacy

Rare360 is committed to protecting participant privacy.


Where practicable:

  • personally identifiable information shall be maintained separately from research responses;

  • research data shared with clients shall be de-identified or pseudonymized;

  • only the minimum information necessary shall be collected.


Rare360 does not sell participant personal information.
 

15. Fraud Prevention

Rare360 utilizes layered controls to reduce fraudulent participation, including:

  • eligibility verification;

  • duplicate detection;

  • response consistency review;

  • manual quality assurance;

  • respondent validation;

  • AI-generated response quality review.
     

16. Logging & Monitoring

Where supported by cloud platforms and applications, Rare360 maintains security logging for:

  • authentication events;

  • administrative actions;

  • account changes;

  • security alerts;

  • malware events.


Logs are reviewed during incident investigations and retained according to business and legal requirements.
 

17. Backup & Recovery

Business information shall be protected through encrypted cloud-based backups provided by approved service providers.


Backups shall:

  • utilize encryption at rest;

  • support disaster recovery;

  • be accessible only to authorized personnel.
     

18. Physical Security

Rare360 primarily utilizes secure cloud infrastructure.


Cloud providers are responsible for physical security of production environments.


Rare360 personnel shall safeguard company devices through:

  • secure storage;

  • automatic locking;

  • restricted physical access;

  • immediate reporting of lost devices.
     

19. Third-Party Vendors

Rare360 evaluates third-party vendors based upon:

  • security practices;

  • privacy protections;

  • contractual obligations;

  • ability to safeguard participant information.


Vendors processing confidential information may be required to execute confidentiality agreements or data processing agreements.
 

20. Security Awareness

Personnel with access to confidential information shall receive security and privacy awareness training appropriate to their role.


Training includes:

  • phishing awareness;

  • password security;

  • data handling;

  • incident reporting;

  • privacy obligations.
     

21. Acceptable Use

Personnel shall:

  • use Rare360 information only for authorized business purposes;

  • protect confidential information from unauthorized disclosure;

  • immediately report suspected security incidents;

  • comply with all security procedures.


Unauthorized copying, sharing, or misuse of confidential information is prohibited.
 

22. Compliance

Violations of this policy may result in disciplinary action, termination of access privileges, contractual remedies, or other appropriate action.
 

23. Policy Governance

This policy shall be reviewed at least annually and updated as necessary to reflect:

  • changes in technology;

  • changes in legal requirements;

  • emerging cybersecurity threats;

  • organizational changes;

  • lessons learned from security incidents.
     

24. Contact

Questions regarding this policy should be directed to:

Rare360

Email: admin@rare360.life

bottom of page