
Information Security Policy
Last Updated: July 27, 2026
This Information Security Policy describes the security principles, controls, and practices implemented by ALLE TECH LLC FZ (“ALLE TECH”, “we”, “our”, or “us”) to protect customer information, business data, software platforms, and technology services.
This Policy applies to all ALLE TECH products, software solutions, ERP implementations, cloud services, consulting engagements, custom software development, support services, infrastructure, employees, contractors, and authorized third-party providers involved in delivering our Services.
1. Our Security Commitment
At ALLE TECH, information security is fundamental to our business. We are committed to maintaining the:
- Confidentiality of customer information
- Integrity of business and system data
- Availability of our services and infrastructure
We implement commercially reasonable administrative, technical, physical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, destruction, misuse, or loss.
2. Scope
This Policy applies to:
- Corporate Website & Customer Portals
- Odoo & SAP Business One Solutions
- Cloud & Mobile Applications
- APIs and Integrations
- AI-powered Solutions
- Custom Software Development
- Technical Support & Managed Services
- Internal Corporate Systems
It also applies to all employees, contractors, consultants, partners, and authorized service providers handling ALLE TECH or Customer information.
3. Cloud Infrastructure
ALLE TECH utilizes reputable cloud infrastructure providers to deliver secure and reliable services. Depending on the solution deployed, infrastructure may include providers such as:
- Amazon Web Services (AWS)
- Microsoft Azure
- Google Cloud Platform (GCP)
- Odoo Cloud
- SAP-approved hosting providers
- Other enterprise cloud providers
These platforms provide enterprise-grade capabilities including:
- Physical security & environmental controls
- Infrastructure redundancy & continuous availability features
- Network security & disaster recovery capabilities
ALLE TECH leverages these services to support secure delivery of customer solutions.
4. Data Encryption
Data in Transit
All communications between users and ALLE TECH systems are protected using industry-standard encryption protocols, including HTTPS and TLS. Where applicable, secure APIs and encrypted communication channels are used between integrated systems.
Data at Rest
Customer information stored within supported environments is protected using commercially reasonable security measures. Where technically appropriate and supported by the underlying platform, sensitive information may be encrypted at rest.
5. Identity and Access Management
Access to customer systems, software environments, and internal resources is granted strictly on the basis of business necessity and the principle of least privilege. Security controls include:
- User authentication
- Role-based access control (RBAC)
- Administrative privilege management
- Segregation of duties
- Multi-factor authentication (where supported)
- Access logging and monitoring
- Periodic access reviews
Customers remain responsible for protecting their own user credentials and administrator accounts.
6. Password Security
ALLE TECH encourages strong authentication practices. Customers and users should:
- Use strong and unique passwords.
- Avoid password sharing.
- Change compromised credentials immediately.
- Enable Multi-Factor Authentication (MFA) whenever available.
- Follow their organization's password policies.
7. Secure Software Development
ALLE TECH follows secure software development practices throughout the application lifecycle. Security measures may include:
- Secure coding standards
- Code reviews
- Controlled deployment processes
- Environment segregation
- Vulnerability remediation
- Dependency management
- Application logging
- Security testing
- Version control
- Change management procedures
Security practices are reviewed and improved on an ongoing basis.
8. Network Security
ALLE TECH maintains commercially reasonable network protection measures, including:
- Firewall protection & secure network segmentation
- Traffic filtering & access restrictions
- Intrusion monitoring & threat detection
- Security event monitoring & continuous infrastructure monitoring
9. Backup and Disaster Recovery
To support business continuity, ALLE TECH maintains backup and recovery procedures appropriate to the Services being delivered. Backup activities may include:
- Database & Configuration backups
- Application backups & Virtual server snapshots
- Document backups & Disaster recovery planning
Backup frequency and retention periods vary according to the applicable customer agreement, platform capabilities, and operational requirements.
10. Security Monitoring and Incident Response
ALLE TECH maintains procedures for identifying, investigating, responding to, and recovering from information security incidents.
Where a confirmed security incident occurs, ALLE TECH will:
- Assess the incident & Contain potential risks.
- Investigate the root cause.
- Implement corrective actions.
- Restore affected services where appropriate.
- Notify affected customers where required by applicable law or contractual obligations.
11. Employee Security Responsibilities
Employees, consultants, and contractors who access customer information are required to:
- Protect confidential information.
- Follow company security procedures.
- Report suspected security incidents promptly.
- Comply with internal information security policies.
- Access customer information only where required for authorized responsibilities.
Access is granted only to personnel with a legitimate business need.
12. Third-Party Providers
ALLE TECH may engage carefully selected third-party providers to support the delivery of our Services. Examples include:
- Cloud hosting & infrastructure providers
- ERP software vendors
- Security providers
- Monitoring & communication platforms
- AI technology providers
- Integration partners
Reasonable efforts are made to select providers that maintain appropriate security standards and contractual confidentiality obligations.
13. Business Continuity
ALLE TECH maintains operational practices designed to support the continuity of our business operations and customer services. Business continuity measures may include:
- Infrastructure redundancy
- Backup procedures
- Disaster recovery planning
- Incident response processes
- Cloud failover capabilities & recovery testing where appropriate
While every reasonable effort is made to ensure continuity, no technology service can guarantee uninterrupted availability.
14. Customer Security Responsibilities
Security is a shared responsibility. Customers remain responsible for:
- Managing user accounts.
- Protecting endpoint devices.
- Maintaining internal IT security.
- Applying vendor updates where applicable.
- User awareness and training.
- Compliance with applicable laws & regulations.
- Appropriate data backup where contractually required.
ALLE TECH cannot be held responsible for security incidents arising from customer negligence, compromised credentials, unsupported customizations, or third-party systems outside our control.
15. Compliance
ALLE TECH designs its products, services, and implementation methodologies to support customer compliance initiatives.
However, each Customer remains solely responsible for ensuring compliance with all laws, regulations, industry standards, and internal governance requirements applicable to its business and jurisdiction.
16. Continuous Improvement
Information security is an ongoing process. ALLE TECH periodically reviews and enhances its:
- Security controls & infrastructure
- Internal procedures & risk management practices
- Incident response capabilities & security awareness programs
to address evolving cybersecurity threats and industry best practices.
17. Policy Updates
ALLE TECH may update this Information Security Policy from time to time to reflect operational, technological, legal, or regulatory changes. Updated versions will be published on:
Continued use of our Services following publication of an updated Policy constitutes acceptance of the revised version.
18. Contact Information
For information security inquiries or to report a suspected security issue, please contact:
Security Team
ALLE TECH LLC FZ
Dubai, United Arab Emirates
Website: https://www.alle-tech.com
Security Email: Yazan@alle-tech.com
General Inquiries: info@alle-tech.com
Support: Yazan@alle-tech.com