Capital Rail Systems Security Policy
Effective Date: August 14, 2026
Version: 1.1
1. Security Commitment
Capital Rail Systems uses administrative, technical, and organizational measures
designed to protect the confidentiality, integrity, and availability of customer
information and the Services.
2. Hosting and Infrastructure
Capital Rail Systems uses cloud-hosted infrastructure and related service
providers to operate the platform.
3. Authentication and Access Control
Access to the application is controlled through authenticated user accounts,
role-based permissions, customer-level access controls, and other authorization
mechanisms implemented within the Services.
4. Transport Security
Capital Rail Systems uses encrypted network connections where reasonably
appropriate to protect information transmitted between users and the Services.
5. Data Storage
Customer information may be stored in cloud databases, object storage, backups,
logs, and other systems reasonably necessary to operate the Services.
6. Account Responsibility
Customers and users are responsible for safeguarding passwords and other account
credentials and for promptly reporting suspected unauthorized access.
7. Security Monitoring and Maintenance
Capital Rail Systems may perform software updates, security patches, logging,
monitoring, backups, and other activities intended to maintain the security and
reliability of the Services.
8. Security Incidents
If Capital Rail Systems becomes aware of a security incident affecting customer
information, it may investigate the event, take appropriate mitigation measures,
and provide notifications when required by applicable law or contract.
9. Customer Responsibilities
Customers are responsible for maintaining appropriate security practices within
their own organizations, including user access management, endpoint security,
credential protection, and timely removal of access for personnel who no longer
require it.
10. No Absolute Security Guarantee
No system can be guaranteed to be completely secure. Capital Rail Systems does
not warrant that unauthorized access, cybersecurity incidents, or data loss can
never occur.