Information Security
How CulperSec protects customer data, operates its systems, and governs security.
- Documentation
- Standard due diligence package
- Availability
- Customers and prospects under mutual NDA
- Information updated
- December 9, 2025
01
Infrastructure and data security
CulperIQ uses a security-first architecture centered on defense in depth, continuous monitoring, proactive threat prevention, and control at each layer of the technology stack.
02
Payment security
CulperSec uses a fully outsourced payment model. Cardholder data remains outside CulperSec-managed systems, and applicable controls align with the organization's PCI DSS scope.
03
CulperSec policies
All staff are accountable for understanding and following CulperSec information security policies covering access, risk, change, incident response, data handling, secure development, and related responsibilities.
04
Additional policy coverage
CulperSec also maintains internal corporate policies across the following operational and technical areas.
- Acceptable Use Policy
- Antivirus/Antimalware Policy
- Asset Management / Inventory Policy
- Change Management Policy
- Clear Desk and Clear Screen Policy
- Cryptography Policy
- Data Classification and Handling Policy
- Logging Policy
- Patch Management Policy
- Physical/Environmental Security Policy
- Awareness Training Policy
- Mobile Device Policy
- IoT Security Policy
- Vulnerability Management Policy
- Removable Media Policy
Need detailed security documentation?
Contact CulperSec to request the standard due diligence package or discuss a security review.