Skip to content
Turasistan

Information Security Policy

●  Turasistan Information Security

Information Security Policy

 

At Turasistan, we implement comprehensive information security measures to protect the confidentiality, integrity, and availability of customer data.

ISP
ISO 27001
KVKK & GDPR Compliance
3-Tier Security

Purpose and Scope

 

This policy has been prepared to ensure the security of all information assets processed through the Turasistan platform.

The policy covers our employees, customers, business partners, and all real and legal persons using our platform. Turasistan takes all necessary administrative and technical measures under the Personal Data Protection Law No. 6698 (KVKK) and the European Union General Data Protection Regulation (GDPR).

Our information security management system aims to comply with the ISO 27001 standard, KVKK, GDPR, and relevant industry regulations.

Our Core Principles

 

Our information security approach is built on three core principles: confidentiality, integrity, and availability.

✓

Confidentiality

Only authorized personnel can access information. Customer data is stored encrypted and is not shared with third parties.

◎

Integrity

Data is ensured to be accurate, complete, and unaltered. Protection against unauthorized modifications is applied.

✦

Availability

Authorized users can securely access information and systems when they need them.

Security Measures We Apply

 

3-Tier Security Architecture: Turasistan operates on a 3-Tier technology architecture preferred by banks. The system runs and is backed up on 3 different physical servers.

Firewall and Antivirus Protection: Dedicated firewall and antivirus solutions provide both hardware and software protection against threats.

Encryption: Customer information and all sensitive data are stored fully encrypted.

Access Control: Only authorized personnel can access information. User data is not shared with third parties without the user's consent.

Legal Compliance

 

We conduct our activities in full compliance with applicable national and international legislation.

KVKK (Law No. 6698)

We fulfill our obligations as data controller under the Personal Data Protection Law.

GDPR (EU General Data Protection Regulation)

We comply with GDPR principles when processing the data of European Union citizens.

ISO 27001

Our Information Security Management System (ISMS) processes are carried out in line with the ISO 27001 standard.

Responsibilities and Incident Reporting

 

Information security is a shared responsibility across the entire team. All our employees and business partners are obliged to comply with this policy.

Employee Responsibilities

All employees participate in information security awareness training and comply with security procedures.

Incident Reporting

Any security breach or suspicious situation must be reported immediately to the information security team.

Enforcement

Disciplinary processes are applied to employees who do not comply with the policy.

Do you have questions?

Contact us for more information about our information security policy or data protection practices.

Contact Us

You can reach our information security team to submit your questions.

Contact Us

Turasistan • Information Security Policy • Data Protection