Version: 1.6 - June 2023

Introduction

At Warp VR it is our mission to enable people to get the most out of themselves. In order to do that we believe that making sure trainee data is secure and guarded is our greatest responsibility. We fully comply with EU data security laws. Furthermore our service providers are known for their online and offline security measures and reliability of data storage.

Organizational security

Data security is one of our most important topics. Our customers and their trainees should fully trust us to handle their data in the most secure manner. To guarantee the level of our data security we work with the best services providers who are known for their secure infrastructure and software.

Employee security

Our data security program is known to all our employees at Warp VR - programmers, employees, freelancers - who have direct access to our internal information system or have access to our office. They are all aware of the data security procedures and standards.

Before an employee at Warp VR receives access to our system, they are required to sign a non disclosure agreement, pass a screening and follow a security training. This security training contains many subjects like malware, data security on location, data privacy and incident reporting.

When we terminate an employee or freelancer contract all access to our information systems is immediately revoked.

Security and privacy training

Every year Warp VR employees must follow and pass a mandatory privacy & security training. They also need to confirm they have read and understood the Warp VR Data Security Policy. Employees with higher clearance levels, such as programmers and support employees, receive additional training.

OWASP

When implementing new code we always check this according to the OWASP Top 10. These are vulnerabilities that are known by security experts as the most critical for web applications:

  1. Injection
  2. Broken authentication and session management
  3. Cross-site scripting (XSS)
  4. Insecure direct objectreference