Independence, Privacy & Security Charter
Our Commitment
At FIDELIR, our mission is to strengthen the resilience, security, and trust of the organisations we serve. We believe cybersecurity is built on independence, transparency, and unwavering respect for our clients’ sovereignty over their data and infrastructure.
The following principles define how we operate — not as marketing slogans, but as binding operational guardrails.
1. Client Interests Come First
Our sole professional responsibility is to protect the interests of our clients. We do not engage in any activity that compromises our clients’ security, privacy, or operational resilience for the benefit of any third party — governmental, commercial, or otherwise.
2. No Voluntary Cooperation
We do not voluntarily provide governments, intelligence agencies, law enforcement, or any third party with access to our clients' systems, infrastructure, confidential information, or operational data. Any disclosure of information will occur only where we are legally compelled to do so under applicable law, and never as a matter of courtesy or expediency.
3. No Backdoors
We do not design, develop, deploy, or recommend technologies that intentionally weaken security or contain hidden access mechanisms ("backdoors"). Security should protect users — not create privileged access for anyone. Where we integrate third-party products, we conduct independent code and configuration reviews to mitigate the risk of latent vulnerabilities introduced by vendors.
4. Privacy by Design
Our consulting services, managed security operations, and resilience solutions are architected according to internationally recognized security principles, including:
- Security by Design
- Privacy by Design
- Zero Trust Architecture
- Least Privilege
- Defence in Depth
- Secure-by-Default Configuration
5. Data Minimization & Purpose Limitation
We collect, process, and retain only the information strictly necessary to deliver our services. Access to client systems and data is limited to the scope of the agreed engagement, retained only for the contractually defined period, and never used for any purpose other than the agreed service. Wherever technically feasible, we design solutions to minimise or eliminate our own persistent access to customer data.
6. Transparency & Notification
Where legally permitted, we will promptly notify affected clients of any government or regulatory request concerning their information or infrastructure. We are committed to publishing periodic Transparency Reports summarising legally permissible statistics regarding official requests for customer information.
7. Legal Due Process
Every official request for information is carefully reviewed by our legal and security teams. We comply only with legally valid and binding requests issued by competent authorities under applicable law. Where permitted, we will challenge requests that are unlawful, overly broad, or inconsistent with fundamental principles of privacy, due process, or proportionality.
8. Independence
Our professional judgment remains independent of political, commercial, or governmental influence. We do not participate in mass surveillance programs or activities intended to facilitate unauthorised monitoring of our clients. Where we provide both assurance and implementation support, we segregate those roles — separate engagement scope and, where needed, separate team — so that an assurance opinion is not compromised by advisory work on the same subject matter.
9. Responsible Security
As trusted advisors, we are committed to responsible disclosure, ethical security research, and internationally recognised best practices. We will never intentionally introduce vulnerabilities into client environments or compromise the confidentiality, integrity, or availability of their systems.
10. Staff Integrity & Insider Accountability
Trust is not just about technology — it is about the people who operate it.
- Rigorous vetting. Every employee with access to client systems undergoes comprehensive background screening in line with applicable legal and industry standards.
- Least privilege for our own staff. Even our senior engineers are granted access only to the minimum resources necessary for their tasks, and for the shortest time required.
- Full auditability. All actions performed by our personnel within client environments are logged, time-stamped, and attributable. Clients can request these audit trails at any time.
- Contractual and ethical obligations. All team members sign strict non-disclosure and ethics agreements, which remain in force even after their employment ends.
- Zero tolerance. Any attempt to misuse access, disclose confidential information, or engage in conflicts of interest will result in immediate termination and, where appropriate, referral to law enforcement.
We protect your data not only from external attackers, but also from internal threats — including those that might originate from within our own ranks.
11. Trust Through Accountability
Trust is earned through consistent actions — not marketing claims. We continuously improve our security practices, welcome independent assessments, and remain accountable for the quality and integrity of the services we provide.
Our Promise
We build resilient organisations — not surveillance capabilities. We strengthen security without compromising privacy. We protect our clients’ interests with integrity, independence, and professional excellence.
No hidden access. No undisclosed compromises. No conflicts of interest.