Third Party Index

Snapshot 32324

Document
Security page
URL
https://onlinemediasolutions.com/security/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
110994 bytes
SHA-256 (raw)
1e4473db17b501f84f28fc4b08ebc12c228db3e5b6046fdb004b75c6511cdc50
SHA-256 (normalized text)
741be12683bf109d056f23ee57c85db92f473b38070b449b6e5aef543c57da86

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security
INFORMATION SECURITY POLICY
Last Updated: September 2026
Online Media Solutions Ltd. (“OMS,” “we,” “us,” or “our”) is committed to maintaining appropriate technical and organizational measures designed to protect the confidentiality, integrity, and availability of information and Personal Data processed in connection with our services.
This Information Security Policy (“Policy”) provides an overview of the security practices maintained by OMS as of the “Last Updated” date above.
Our information security practices take into account the nature, scope, context, and purposes of the processing performed by OMS, as well as the risks associated with such processing. OMS periodically reviews its security practices and technical controls in response to changes in technology, identified security risks, applicable laws and regulations, and our business operations.
Security Governance
OMS maintains information and cybersecurity practices designed to identify, assess, and manage security risks relating to our systems, services, personnel, and data.
Security responsibilities are assigned to appropriate personnel within OMS. OMS periodically reviews its information security practices and technical controls based on identified risks, operational requirements, changes to its systems, and developments in the security threat environment.
Employees and contractors are required to comply with applicable OMS security and confidentiality requirements.
System and Access Control
Access to OMS systems is restricted to authorized personnel and is provided according to business requirements and the principle of least privilege.
OMS uses authentication and access-control measures designed to prevent unauthorized access to systems and information. Depending on the applicable system, these measures include passwords, two-factor authentication, restricted administrative access, and other appropriate access controls. Multi-factor authentication is required for access to certain core systems.
Access rights are granted according to job responsibilities and are modified or revoked when an employee or contractor changes responsibilities or leaves OMS.
Remote access to sensitive systems is restricted and subject to appropriate authentication and access controls.
Data Access Control
Access to Personal Data and other sensitive information is limited to personnel who require such access to perform authorized business functions.
OMS implements technical and organizational controls designed to prevent information from being accessed, modified, copied, disclosed, transferred, or deleted without appropriate authorization.
Where appropriate, system and application activity is logged to support security monitoring, investigation, auditing, and troubleshooting.
Encryption and Data Transmission
OMS uses encryption and secure communication protocols designed to protect information transmitted over public networks.
Communication between OMS systems, clients, service providers, and partners is protected using HTTPS/TLS or other appropriate secure communication mechanisms where applicable.
OMS applies encryption at rest across its systems where supported and appropriate, taking into account the sensitivity of the information, the applicable technology, and identified security risks. Certain infrastructure, storage systems, and third-party software components provide built-in encryption at rest where supported and configured.
OMS periodically evaluates its security controls based on the sensitivity of the information being processed, the applicable technology, and identified security risks.
Cloud, Infrastructure, and Network Security
OMS uses infrastructure and service providers to operate portions of its technology environment.
OMS maintains technical controls designed to protect its systems and infrastructure against unauthorized access and malicious activity. Depending on the applicable system, these controls may include identity and access management, network security controls, endpoint protection, malware detection, system configuration controls, logging and monitoring, vulnerability scanning, backup mechanisms, and restricted administrative access.
Physical and environmental security for infrastructure hosted by third-party cloud or data-center providers is managed primarily by the applicable providers according to their respective security practices.
Vulnerability Management
OMS regularly performs vulnerability scanning and monitors known vulnerabilities affecting its systems and applications.
Identified vulnerabilities are evaluated and addressed based on their severity, potential impact, and the affected system.
OMS may use automated vulnerability scanning, software and dependency monitoring, security updates, patching, and other remediation measures as appropriate to the applicable system and identified risk.
Application and Development Security
Security considerations are incorporated into the development and maintenance of OMS applications and services.
OMS applies technical and operational measures intended to reduce application security risks. Depending on the applicable system and development process, these may include access restrictions, testing, software and dependency updates, vulnerability assessment, and separation of development and production environments.
Changes to production systems are limited to authorized personnel.
Logging and Security Monitoring
OMS maintains logging and monitoring capabilities designed to assist with identifying security events, investigating incidents, troubleshooting systems, and maintaining the integrity and availability of its services.
Security-relevant events may be logged and retained for an appropriate period based on operational, security, and legal requirements.
Access to security logs is restricted to authorized personnel.
Security Incident Management
OMS maintains operational practices for identifying, escalating, investigating, containing, and responding to information security incidents.
Potential security incidents are assessed by appropriate personnel based on their severity and potential impact, and appropriate technical and operational actions are taken in response.
Where a security incident involves Personal Data, OMS evaluates applicable notification and reporting obligations and notifies affected customers, authorities, or other parties when required by applicable law or contractual obligations.
OMS reviews significant security incidents as appropriate to identify corrective actions and opportunities to improve its security controls.
Service Resilience and Disaster Recovery
OMS maintains operational disaster-recovery measures designed to support the availability and recovery of its systems and services.
Depending on the relevant system, these measures may include backups, infrastructure redundancy, system monitoring, and recovery mechanisms.
OMS reviews its infrastructure and recovery capabilities as operational requirements and technologies change.
Third-Party and Service Provider Security
OMS limits third-party access to its systems, data, and Personal Data. Third parties are not provided access to OMS data unless such access is necessary for the provision of an authorized business, infrastructure, or technical service.
Where third-party access is required, access is limited to the information and systems reasonably necessary for the relevant service and is subject to appropriate access controls and security measures.
Third-party service providers that access or process Personal Data or other sensitive information on behalf of OMS are subject, where applicable, to contractual obligations addressing confidentiality, privacy, data protection, and information security.
OMS considers the nature of the services provided and the associated security and privacy risks when engaging service providers. Third-party access to OMS systems or data is restricted or discontinued when it is no longer required for the applicable service.
The use of a third-party service provider does not, by itself, provide that provider with unrestricted access to OMS systems or data.
Personnel Security and Awareness
Employees and relevant contractors are subject to confidentiality and security obligations.
Where permitted and appropriate under applicable law, OMS may conduct screening as part of its employment or engagement processes.
Personnel receive information security and privacy awareness appropriate to their responsibilities, including periodic training and security guidance where applicable.
Access to systems and Personal Data is granted only where required for authorized responsibilities and is removed when no longer necessary.
Physical Security
OMS maintains appropriate physical security measures for OMS-controlled facilities.
Access to areas containing sensitive systems or information is limited to authorized personnel.
Physical security for infrastructure hosted by third-party cloud and data-center providers is managed by those providers according to their respective physical and environmental security practices.
Data Retention and Secure Deletion
OMS retains Personal Data and other information only for as long as reasonably necessary for the purposes for which it was collected or processed, including applicable business, security, contractual, and legal requirements.
Information is deleted, anonymized, or otherwise disposed of in accordance with applicable retention requirements and OMS practices when it is no longer required.
Privacy and Data Protection
OMS maintains security measures intended to support its obligations under applicable privacy and data-protection laws, including, where applicable, the EU General Data Protection Regulation (“GDPR”).
Security measures are selected taking into account factors such as the nature of the information, processing activities, available technology, implementation considerations, and risks to individuals.
This Policy should be read together with OMS’s Privacy Notice and applicable Data Processing Agreements.
Contact
Questions, concerns, or reports relating to this Policy or to the security of OMS systems and data can be directed to OMS through our contact page at https://onlinemediasolutions.com/contact/. OMS reviews communications received through this channel and responds as appropriate based on the nature of the request.
Review and Updates
OMS periodically reviews its information security practices and this Policy to account for changes in technology, business operations, applicable laws and regulations, and the cybersecurity threat environment.
Security controls may be modified or enhanced based on identified risks, security reviews, incidents, vulnerability findings, technological developments, or changes to OMS services.
This Policy may be updated from time to time. The version published on the OMS website represents the current version of the Policy.