Trust and security
Security Framework and Best Practice Standards
The global frameworks, cloud controls, and operational practices we use to protect geospatial analytics and location-based data throughout its lifecycle.
Last updated:
Introduction
At Maddict, We understand that the value of Our services depends on the trust customers place in Us to handle geospatial analytics and location-based data securely and responsibly. This information can include geolocation coordinates, spatial intelligence, and derived analytics, and it requires a rigorous, well-governed, and standards-driven approach to protection.
Our security frameworks guide every stage of the data lifecycle, from ingestion and processing to analysis and distribution, in line with recognized global standards and regulatory expectations.
Operating primarily in the Google Cloud Platform ecosystem, Our architecture uses native capabilities such as Cloud Identity and Access Management, VPC Service Controls, and Cloud DLP to protect sensitive location data and support consistent compliance monitoring across environments.
Through these frameworks and the continuous evaluation of Our controls, Maddict demonstrates its commitment to the confidentiality, integrity, and availability of geospatial and location-based data assets.
Core frameworks adopted at Maddict
Our program combines governance, risk, operational, cloud, and privacy standards. The table summarizes each framework's role and the current depth of coverage described by Maddict's security standard.
| Framework or standard | Relevance | Depth of coverage |
|---|---|---|
| NIST Cybersecurity Framework (CSF 1.1) | Provides a structured approach for managing cybersecurity risk across the organization. | Full adoption across the five core functions: Identify, Protect, Detect, Respond, and Recover. |
| CIS Controls v8 and CIS GCP Foundations Benchmark | Ensures that GCP configurations align with industry security and compliance practices. | Comprehensive implementation across GCP projects, IAM, networking, and logging configurations. |
| ISO/IEC 27001:2022 | Establishes an Information Security Management System (ISMS) across operations. | Implemented organization-wide, covering people, process, and technology. |
| NIST SP 800-53 Rev. 5 (Moderate Baseline) | Provides detailed control mapping for sensitive location and geospatial data systems. | Partially adopted for cloud workloads handling geospatial data and APIs. |
| GDPR, CCPA, and data-localization laws | Governs lawful handling and protection of personal and geolocation data. | Applied to data collection, processing, and retention practices. |
GCP-specific internal practices
These controls translate the adopted frameworks into day-to-day safeguards across identity, data protection, monitoring, vulnerability management, and incident response.
| Control area | Framework reference | Implementation |
|---|---|---|
| Identity and Access Management | NIST SP 800-63B / CIS Control 6 | Least-privilege access, segregated service accounts, multi-factor authentication, and IAM Recommender audits. |
| Data Protection | NIST SP 800-57 / CIS Control 3 | Encryption at rest with CMEK/KMS and in transit with TLS 1.2+, SHA-256, and geo-fencing of sensitive data across multiple databases. |
| Monitoring and Logging | NIST SP 800-137 / CIS Control 8 | Cloud Logging and Monitoring, real-time alerting, and Security Command Center for threat detection. |
| Vulnerability Management | NIST SP 800-40 / CIS Control 7 | Automated scanning through Security Health Analytics and Container Analysis, with regular patch management. |
| Incident Response | NIST SP 800-61 | Response playbooks integrated with Cloud Functions and Pub/Sub for automated workflows. |
Scope of coverage
Environment
All Maddict GCP-based projects, including Compute Engine, BigQuery, Cloud Storage, and Google Kubernetes Engine clusters.
Data types
Location data, user metadata, geospatial analytics outputs, and related API logs.
Users
Internal engineering teams, data scientists, and authorized clients accessing services through secured APIs.
Regions
Data is hosted within Bahrain to support KSA PDPL data-residency requirements.
Secure software delivery
Maddict uses continuous integration and continuous deployment practices, with GitHub Actions automating software-development workflows including code builds, testing, and deployment.
Reporting a security vulnerability
We welcome reports from security researchers. If You believe You have found a vulnerability, email security@maddict.net. Our machine-readable disclosure policy is available at /.well-known/security.txt.
What to include
- A clear description of the issue and its potential impact.
- Step-by-step instructions that reproduce the issue.
- Any proof of concept, affected URLs, and Your contact details.
Coordinated disclosure and safe harbor
We will acknowledge Your report, keep You updated as We investigate and remediate, and ask that You give Us a reasonable opportunity to resolve the issue before public disclosure.
We will not pursue legal action against researchers who act in good faith and follow this policy. Good-faith research means You:
- Do not access, modify, or delete data that is not Your own.
- Do not degrade, disrupt, or run denial-of-service tests against the Service.
- Do not exfiltrate data, and stop testing once a vulnerability is confirmed.
- Comply with applicable law.