Legal

    Information Security Policy

    Last updated: October 1, 2026

    1. Purpose

    Protecting information, and the systems that store and process it, is of strategic importance to Purtera LLC, a Georgia limited liability company ("PurTera," "PurTera IT," "we," "us," or "our"). Our customers trust us with access to their sites, networks, and data, and our ability to deliver depends on keeping that trust.

    This policy states PurTera's commitment to information security and the principles we follow to protect the information we hold, whether it belongs to us, our customers, our partners, or our people.

    2. Scope

    This policy applies to:

    • All PurTera employees, contractors, field technicians, and partners who have access to PurTera information or systems.
    • All information PurTera creates, receives, stores, or transmits, in any form, including information we handle on behalf of our customers.
    • All systems, applications, devices, and services used to process that information.

    3. Objectives

    PurTera's information security objectives are to:

    • Protect the confidentiality, integrity, and availability of the information we manage.
    • Keep our information systems operating properly and reliably.
    • Respond promptly to incidents that could affect our operations or our customers.
    • Meet our legal, regulatory, and contractual obligations.
    • Keep improving our level of information security.

    4. How we meet these objectives

    To meet these objectives, PurTera is committed to:

    • Making responsibility for information security clear across the company.
    • Limiting access to information and systems to the people who need it for their role, and protecting accounts with strong authentication.
    • Handling information according to its sensitivity and value.
    • Protecting information while it is stored, processed, and transmitted, including through encryption.
    • Making sure employees, contractors, and partners understand their information security responsibilities.
    • Identifying, reporting, and responding to security incidents promptly.
    • Keeping our operations running, and recovering quickly, if systems fail or a disaster occurs.
    • Taking information security into account when choosing and working with suppliers and service providers.

    5. Risk management and review

    PurTera is committed to identifying and assessing the risks to the information we hold, taking appropriate measures to address them, and reviewing how well our safeguards are working so that we keep improving.

    6. Responsibilities

    PurTera's management approves this policy and is responsible for information security at PurTera. That includes providing the resources needed to carry out this policy and acting to reduce or remove anything that could put the availability, integrity, or confidentiality of PurTera's information at risk.

    Everyone with access to PurTera information or systems is required to follow this policy and the procedures that support it. Failure to do so may lead to disciplinary action or termination of the working relationship.

    7. Legal and regulatory compliance

    PurTera is committed to complying with the United States federal and state laws that apply to our business, including data security and breach notification laws, and with the security requirements in our customer agreements. If a security incident affects customer or personal information, we will notify the affected customers and individuals as required by law and by contract. How we handle personal information is described in our Privacy Notice.

    8. Reporting a security concern

    If you believe you have found a vulnerability or have a security concern involving PurTera, email security@purtera-it.com. More detail on our security practices and compliance status is on our Security & Compliance page.

    9. Review of this policy

    PurTera reviews this policy periodically, and whenever our business, technology, or legal requirements change significantly, and updates it as needed. The current version is always available on this page.