Privacy Policy
WebCastle’s published privacy policy, covering personal data handling, cookies, data subject requests and contact details.
Available now.
Owner: WebCastle
Resources
WebCastle’s security policy library — what exists today, what is in development, and how to request documentation for a security review.
Reviewed 12 August 2026
WebCastle is building a formal security policy set. Several policies are drafted and moving through internal review; none has yet completed management approval, so none is published here as an approved document.
This is a deliberate choice. Publishing a policy implies it is approved, in force and being followed. Until that is true, this page reports the actual state of each document instead.
Where a security review needs detail before the policy set is published, the security team can provide written control descriptions covering the specific areas you need, under NDA where appropriate.
Documents WebCastle publishes today.
WebCastle’s published privacy policy, covering personal data handling, cookies, data subject requests and contact details.
Available now.
Owner: WebCastle
Drafted and moving through internal review. Not yet approved for publication.
The overarching policy setting out WebCastle’s security objectives, governance, ownership and the scope of the security program.
Drafted and in internal review. Not yet approved for publication.
Owner: Technical leadership
Account lifecycle, least privilege, privileged access, authentication requirements and periodic access reviews.
Drafted and in internal review. Not yet approved for publication.
Owner: Technical leadership
Password requirements, multi-factor authentication expectations and the handling of shared and default accounts.
Drafted and in internal review. Not yet approved for publication.
Owner: Technical leadership
How security incidents are identified, classified, contained, investigated, remediated and communicated.
Drafted and in internal review. Not yet approved for publication.
Owner: Technical leadership
Data classification, handling, storage, transmission, retention, deletion and customer data segregation.
Drafted and in internal review. Not yet approved for publication.
Owner: Technical leadership
Secure development lifecycle, code review, environment separation, dependency management and deployment controls.
Drafted and in internal review. Not yet approved for publication.
Owner: Engineering
Scheduled for drafting as the security program develops.
Continuity approach, backup strategy, recovery planning, service restoration and customer communication.
Scheduled for drafting as part of the security program.
Owner: Technical leadership
Identification, assessment, prioritisation and remediation of vulnerabilities across applications and infrastructure.
Scheduled for drafting as part of the security program.
Owner: Engineering
Vendor selection, security review, ongoing oversight, data processing arrangements and offboarding.
Scheduled for drafting as part of the security program.
Owner: Technical leadership
Expected use of WebCastle systems, accounts and devices, and the responsibilities that apply to everyone at WebCastle.
Scheduled for drafting as part of the security program.
Owner: Operations
If your review requires documentation that is not published here, contact the security team with the specific areas you need covered. WebCastle can complete your security questionnaire, provide written control descriptions, and sign an NDA where the discussion calls for it.