Rare360 Information Security Policy
Document Owner: Data Protection & Information Security Manager
Approved By: Rare360 Executive Management
Effective Date: January 1, 2026
Review Cycle: Annually or upon material changes to the business or technology environment
Version: 1.0
1. Purpose
Rare360 is committed to protecting the confidentiality, integrity, and availability of the information entrusted to us by research participants, caregivers, clients, employees, and business partners.
This Information Security Policy establishes the administrative, technical, and organizational safeguards implemented to protect information assets and reduce the risk of unauthorized access, disclosure, alteration, destruction, or interruption.
2. Scope
This policy applies to:
-
All Rare360 personnel
-
Contractors and temporary workers
-
Consultants
-
Third-party service providers with access to Rare360 information
-
All systems processing Rare360 information
-
Cloud-based applications
-
Mobile devices authorized for business use
3. Information Security Principles
Rare360's security program is based upon the following principles:
-
Least privilege
-
Need-to-know access
-
Defense in depth
-
Data minimization
-
Privacy by Design
-
Secure cloud-first architecture
-
Continuous improvement
-
Risk-based security management
4. Information Classification
Information shall be classified as:
Public: Information approved for public release.
Internal: Routine business information not intended for public disclosure.
Confidential: Client information, contracts, internal business records, financial information.
Restricted: Personally identifiable information (PII), protected health information (PHI) where applicable, participant contact information, authentication credentials, and other highly sensitive information requiring the highest level of protection.
5. Access Control
Access to information shall be granted only:
-
for legitimate business purposes;
-
using the principle of least privilege;
-
based upon job responsibilities.
Access shall be reviewed periodically.
Accounts shall be disabled promptly following termination of employment or business need.
Shared user accounts are prohibited except where technically unavoidable and formally approved.
6. Authentication
Rare360 requires strong authentication controls.
Requirements include:
-
Unique user IDs
-
Strong passwords or passphrases
-
Multi-factor authentication where supported for systems containing confidential information
-
Automatic session timeouts
-
Automatic screen locking
-
Protection against repeated failed login attempts
Passwords shall never be shared.
7. Encryption
Data at Rest
Sensitive information shall be protected using industry-standard encryption (AES-256 or equivalent) where supported.
This includes:
-
Cloud storage
-
Databases
-
Backups
-
Mobile devices
Data in Transit
Sensitive information shall be encrypted using:
-
TLS 1.2 or higher
-
HTTPS
-
Secure APIs
-
Secure file transfer protocols
Transmission of confidential information over unsecured channels is prohibited.
8. Endpoint Security
Company-managed systems shall utilize:
-
Endpoint anti-malware protection
-
Automatic security updates
-
Operating system patching
-
Device authentication
-
Screen lock
-
Encryption where supported
Unauthorized software installation is prohibited.
9. Mobile Device Security
Rare360 authorizes limited business use of a secure Android mobile device for respondent communications.
Requirements include:
-
Full-device encryption
-
Strong PIN/password
-
Biometric authentication where enabled
-
Automatic screen lock
-
Current Android security updates
-
Authorized users only
Only the minimum information necessary should be accessed or stored on the device.
Lost or stolen devices shall be reported immediately.
10. Vulnerability & Patch Management
Rare360 follows a risk-based patch management process.
Critical security updates shall be prioritized.
Cloud service providers are responsible for maintaining the security of the underlying infrastructure.
Rare360 remains responsible for:
-
customer-managed configurations;
-
application settings;
-
account security;
-
timely software updates under its control.
11. Malware Protection
Endpoint protection shall provide:
-
Real-time protection
-
Automatic signature updates
-
Malware scanning
-
Quarantine capabilities where supported
Suspected malware incidents shall be reported immediately.
12. Incident Response
Rare360 maintains an incident response process consisting of:
-
Identification
-
Assessment
-
Containment
-
Investigation
-
Eradication
-
Recovery
-
Post-incident review
Incidents involving personal information shall be managed in accordance with applicable legal, contractual, and regulatory obligations.
13. Data Retention & Destruction
Personal information shall be retained only as long as necessary to:
-
fulfill business purposes;
-
satisfy contractual obligations;
-
comply with legal requirements.
Upon expiration of retention periods, information shall be securely deleted, anonymized, or otherwise destroyed.
14. Respondent Privacy
Rare360 is committed to protecting participant privacy.
Where practicable:
-
personally identifiable information shall be maintained separately from research responses;
-
research data shared with clients shall be de-identified or pseudonymized;
-
only the minimum information necessary shall be collected.
Rare360 does not sell participant personal information.
15. Fraud Prevention
Rare360 utilizes layered controls to reduce fraudulent participation, including:
-
eligibility verification;
-
duplicate detection;
-
response consistency review;
-
manual quality assurance;
-
respondent validation;
-
AI-generated response quality review.
16. Logging & Monitoring
Where supported by cloud platforms and applications, Rare360 maintains security logging for:
-
authentication events;
-
administrative actions;
-
account changes;
-
security alerts;
-
malware events.
Logs are reviewed during incident investigations and retained according to business and legal requirements.
17. Backup & Recovery
Business information shall be protected through encrypted cloud-based backups provided by approved service providers.
Backups shall:
-
utilize encryption at rest;
-
support disaster recovery;
-
be accessible only to authorized personnel.
18. Physical Security
Rare360 primarily utilizes secure cloud infrastructure.
Cloud providers are responsible for physical security of production environments.
Rare360 personnel shall safeguard company devices through:
-
secure storage;
-
automatic locking;
-
restricted physical access;
-
immediate reporting of lost devices.
19. Third-Party Vendors
Rare360 evaluates third-party vendors based upon:
-
security practices;
-
privacy protections;
-
contractual obligations;
-
ability to safeguard participant information.
Vendors processing confidential information may be required to execute confidentiality agreements or data processing agreements.
20. Security Awareness
Personnel with access to confidential information shall receive security and privacy awareness training appropriate to their role.
Training includes:
-
phishing awareness;
-
password security;
-
data handling;
-
incident reporting;
-
privacy obligations.
21. Acceptable Use
Personnel shall:
-
use Rare360 information only for authorized business purposes;
-
protect confidential information from unauthorized disclosure;
-
immediately report suspected security incidents;
-
comply with all security procedures.
Unauthorized copying, sharing, or misuse of confidential information is prohibited.
22. Compliance
Violations of this policy may result in disciplinary action, termination of access privileges, contractual remedies, or other appropriate action.
23. Policy Governance
This policy shall be reviewed at least annually and updated as necessary to reflect:
-
changes in technology;
-
changes in legal requirements;
-
emerging cybersecurity threats;
-
organizational changes;
-
lessons learned from security incidents.
24. Contact
Questions regarding this policy should be directed to:
Rare360
Email: admin@rare360.life
