Legal / Compliance

Information Security Policy

Last updated: August 2, 2026 · Effective for VenueCore Systems operations and customer-facing platforms

VenueCore Systems (“VenueCore,” “we,” “us,” or “our”) maintains this Information Security Policy to document how we identify, mitigate, and monitor information security risks relevant to our business software platforms, websites, and messaging services (including SMS delivered through providers such as Twilio).

1. Purpose and scope

This policy applies to:

2. Security ownership

The VenueCore Systems owner is responsible for approving this policy, assigning access, reviewing incidents, and ensuring security procedures remain operational. Day-to-day security controls are enforced through platform configuration, access restrictions, vendor settings, and documented operating procedures.

Security questions: support@venuecoresystems.com

3. Risk identification

We identify information security risks relevant to our business, including:

Risks are reviewed when systems change, new vendors are added, incidents occur, or before customer go-live decisions.

4. Access control procedures

5. Data protection procedures

6. Vendor and third-party risk

We use vetted service providers for hosting, messaging, and related operations. Providers such as Twilio may process phone numbers and message metadata solely to deliver services on our behalf. Vendor access is limited to the service function required. Material vendor changes are reviewed for privacy, security, and messaging-compliance impact.

7. Monitoring and mitigation

8. Incident response procedure

  1. Detect: Identify the issue through alerts, user reports, vendor notices, or internal review.
  2. Contain: Restrict access, disable affected credentials or integrations, and stop unauthorized messaging if needed.
  3. Assess: Determine systems, data types, and parties affected.
  4. Remediate: Apply fixes, rotate credentials, restore from backup if required, and verify recovery.
  5. Notify: Contact affected customers and, where required, relevant providers or authorities.
  6. Improve: Update controls and this policy if gaps are found.

To report a security concern, email support@venuecoresystems.com.

9. Messaging and communications security

10. Employee / operator expectations

11. Policy review

This Information Security Policy is reviewed at least annually, and sooner after material system changes, security incidents, or new regulatory/provider requirements (including messaging-provider compliance reviews). The published version on venuecoresystems.com is the current customer-facing reference.

12. Related documents

13. Contact

VenueCore Systems
Website: https://venuecoresystems.com
Email: support@venuecoresystems.com