Introduction
Welcome to Just Help Me Foundation (JHMF). Just Help Me Foundation recognizes that information is one of its most valuable organizational assets. The Foundation is committed to protecting the confidentiality, integrity, availability, authenticity, and resilience of all information, digital resources, communication systems, software platforms, databases, cloud infrastructure, payment systems, and technological assets entrusted to the Foundation by its members, donors, volunteers, beneficiaries, employees, applicants, partner organizations, government agencies, financial institutions, service providers, and other stakeholders.
This Universal Information Security Policy establishes the governance framework, security principles, responsibilities, and operational standards for protecting information assets against unauthorized access, cyber threats, accidental disclosure, misuse, alteration, destruction, theft, fraud, ransomware, malware, phishing attacks, insider threats, and other information security risks.
The Foundation is committed to maintaining internationally recognized information security practices while supporting transparency, operational continuity, legal compliance, ethical governance, and public trust.
By accessing, registering, donating, volunteering, applying, communicating, creating an account, using any digital service, or otherwise interacting with any official digital platform of Just Help Me Foundation, every user acknowledges that they have read, understood, and accepted this Universal Information Security Policy together with the Foundation’s Privacy Policy, Data Protection Policy, Terms and Conditions, Cookie Policy, and all other officially published organizational policies.
Scope of this Policy
This Universal Information Security Policy applies to every information asset, digital platform, technology system, communication channel, database, software application, website, cloud service, payment gateway, mobile application, API, electronic document, digital record, authentication system, email service, and every other information processing activity owned, operated, managed, licensed, or authorized by Just Help Me Foundation.
This Policy applies to all official digital properties including but not limited to:
Without limitation, this Policy currently applies to the following official domains:
This Universal Information Security Policy shall automatically apply to every future website, domain, subdomain, mobile application, software platform, cloud infrastructure, payment gateway, API, communication platform, artificial intelligence system, digital verification service, or any other technology officially owned, operated, managed, licensed, or authorized by Just Help Me Foundation without requiring a separate Information Security Policy.
Purpose of this Policy
The purpose of this Policy is to establish a comprehensive information security framework that safeguards the Foundation’s digital assets, protects stakeholder information, strengthens cybersecurity resilience, minimizes operational risks, supports legal compliance, and ensures the continuity of charitable operations.
This Policy aims to promote responsible information management, secure digital transformation, effective cybersecurity governance, secure online transactions, protection of confidential information, prevention of unauthorized access, timely detection of security incidents, and continuous improvement of security controls across all organizational activities.
Information Security Principles
Just Help Me Foundation adopts internationally recognized information security principles designed to protect every category of organizational information.
Information shall be protected against unauthorized access through appropriate authentication, authorization, encryption, monitoring, and access control mechanisms. Information shall be maintained accurately and protected against unauthorized alteration or destruction. Critical systems and services shall remain available through appropriate redundancy, backup procedures, disaster recovery planning, business continuity arrangements, and operational resilience measures.
Every person handling Foundation information shall exercise due care, maintain confidentiality, follow approved security procedures, report security incidents promptly, and cooperate fully with cybersecurity requirements established by the Foundation.
Information Assets Covered
This Policy applies to all forms of information regardless of format or storage medium, including personal information, donor records, membership databases, volunteer information, beneficiary records, financial information, accounting records, payment information, contracts, legal documents, intellectual property, software source code, cloud infrastructure, digital certificates, QR verification systems, research materials, strategic plans, operational manuals, audit reports, email communications, photographs, videos, presentations, mobile applications, APIs, system configurations, server logs, backups, and every other digital or physical information asset belonging to or entrusted to the Foundation.
Security Governance
Information security within Just Help Me Foundation shall be governed through documented policies, organizational procedures, technical safeguards, administrative controls, operational monitoring, risk management practices, employee awareness, security training, periodic assessments, and continuous improvement initiatives.
Every trustee, director, office bearer, employee, volunteer, consultant, contractor, technology provider, and authorized user shares responsibility for protecting organizational information and complying with this Policy according to their respective roles and responsibilities.
Information Classification
Just Help Me Foundation shall classify all organizational information according to its sensitivity, confidentiality, operational importance, legal obligations, and potential impact in the event of unauthorized disclosure, modification, or destruction. Information classification enables the Foundation to apply appropriate security controls proportional to the level of risk associated with each category of information.
Information may be classified as Public Information, Internal Information, Confidential Information, Restricted Information, or Highly Confidential Information. Classification decisions shall consider legal obligations, contractual commitments, donor expectations, regulatory requirements, cybersecurity risks, and organizational priorities.
Every person handling organizational information shall ensure that the information is stored, transmitted, shared, retained, and disposed of in accordance with its designated classification level.
Access Control
Access to organizational information, digital systems, software applications, databases, cloud services, payment systems, communication platforms, and other technological resources shall be granted strictly on the basis of legitimate organizational need, authorized responsibilities, and the principle of least privilege.
Every user shall be provided only the minimum level of access necessary to perform assigned duties. Access rights shall be periodically reviewed and modified whenever responsibilities change, employment or membership ends, security risks are identified, or operational requirements evolve.
Unauthorized access, privilege escalation, credential sharing, circumvention of access controls, or attempts to gain access beyond assigned authorization are strictly prohibited and may result in disciplinary action, suspension of access, legal proceedings, or other corrective measures.
Password and Authentication Policy
Every authorized user shall maintain strong authentication credentials to protect access to organizational systems. Passwords shall be created using appropriate complexity, length, uniqueness, and confidentiality standards designed to reduce the risk of unauthorized access.
Passwords shall not be shared with unauthorized individuals, written in insecure locations, transmitted through unsecured communication channels, reused across unrelated services where reasonably avoidable, or stored in an unprotected manner.
The Foundation may establish password expiration requirements, password history controls, account lockout mechanisms, credential verification procedures, secure password recovery processes, and other authentication safeguards consistent with recognized cybersecurity practices.
Multi-Factor Authentication (MFA)
Just Help Me Foundation may require Multi-Factor Authentication (MFA) for access to administrative systems, cloud services, financial systems, membership databases, donor management platforms, email accounts, payment gateways, digital verification services, and other sensitive organizational resources.
MFA may include one-time passwords, authentication applications, hardware security keys, biometric verification, device-based authentication, or other recognized authentication technologies.
The Foundation reserves the right to require stronger authentication controls whenever elevated security risks are identified.
Network Security
The Foundation shall implement appropriate safeguards to protect organizational networks against unauthorized access, cyberattacks, malware, ransomware, denial-of-service attacks, intrusion attempts, network interception, spoofing, unauthorized scanning, and other network-related threats.
Network security controls may include firewalls, intrusion detection systems, intrusion prevention systems, virtual private networks (VPNs), encrypted communications, network segmentation, traffic monitoring, threat intelligence, secure configuration management, vulnerability management, and continuous security monitoring.
Network infrastructure shall be periodically reviewed to identify vulnerabilities and implement appropriate security improvements.
Server Security
Servers hosting Foundation applications, databases, websites, cloud services, email systems, payment platforms, digital verification services, APIs, or other organizational systems shall be configured and maintained according to recognized information security practices.
Security measures may include operating system hardening, secure configuration management, regular software updates, vulnerability remediation, malware protection, encrypted communications, system monitoring, audit logging, backup procedures, disaster recovery planning, and restricted administrative access.
Administrative access to production servers shall be limited to authorized personnel with legitimate operational responsibilities.
Cloud Security
Where cloud computing services are utilized, Just Help Me Foundation shall make reasonable efforts to select reputable cloud service providers that maintain appropriate technical, organizational, contractual, and regulatory safeguards.
Cloud-hosted information shall be protected through encryption where appropriate, secure authentication, access controls, monitoring systems, backup procedures, incident response planning, disaster recovery capabilities, contractual confidentiality obligations, and other reasonable security measures.
The Foundation may periodically evaluate cloud service providers to ensure continued compliance with organizational security requirements.
Device Security
All computers, laptops, mobile devices, tablets, removable storage devices, network equipment, and other technology used to access Foundation information shall be protected through appropriate security controls.
Security measures may include antivirus software, endpoint detection systems, operating system updates, encryption, password protection, device locking, remote wipe capabilities, secure configuration management, and physical protection against theft or unauthorized access.
Users shall immediately report the loss, theft, compromise, or unauthorized use of any device containing Foundation information.
Email Security
Official email accounts shall be used responsibly and exclusively for legitimate organizational purposes. Users shall exercise caution when opening email attachments, clicking hyperlinks, responding to unexpected requests, or communicating sensitive information electronically.
The Foundation may implement spam filtering, malware detection, email encryption, phishing protection, domain authentication technologies, email monitoring, attachment scanning, and other security measures designed to reduce cybersecurity risks.
Confidential information transmitted through email should be protected using appropriate security measures whenever reasonably practicable.
Physical Security
The Foundation shall implement reasonable physical safeguards to protect offices, server rooms, archives, data centers, storage facilities, communication equipment, workstations, printed records, backup media, and other physical information assets against unauthorized access, theft, fire, vandalism, environmental hazards, accidental damage, or other physical security risks.
Physical security measures may include controlled building access, visitor management procedures, surveillance systems, alarm systems, environmental monitoring, secure storage cabinets, document shredding procedures, asset inventories, and restricted access to sensitive operational areas.
Remote Access Security
Where personnel access organizational systems remotely, such access shall occur only through secure and authorized methods approved by the Foundation. Remote users shall maintain secure internet connections, updated devices, appropriate authentication controls, and comply with all organizational cybersecurity requirements.
The Foundation may require encrypted communications, Virtual Private Networks (VPNs), Multi-Factor Authentication (MFA), endpoint security verification, device compliance checks, session monitoring, and other protective measures before permitting remote access to organizational resources.
Remote access privileges may be suspended, restricted, or revoked whenever security risks, policy violations, technical vulnerabilities, or operational requirements make such action necessary.
Encryption Standards
Just Help Me Foundation is committed to protecting sensitive information through the implementation of appropriate encryption technologies designed to safeguard data during collection, storage, transmission, processing, backup, and archival activities. Encryption serves as a fundamental security control to reduce the risk of unauthorized disclosure, interception, modification, or misuse of organizational information.
Where appropriate, personal information, financial records, payment information, authentication credentials, confidential organizational documents, cloud storage, communication channels, database connections, backup media, APIs, and other sensitive information assets shall be protected using industry-recognized encryption standards and secure cryptographic protocols.
The Foundation reserves the right to periodically review and upgrade its encryption mechanisms in response to technological developments, emerging cybersecurity threats, regulatory requirements, and internationally recognized security standards.
Backup and Disaster Recovery
Just Help Me Foundation shall maintain appropriate backup procedures to protect critical organizational information against accidental loss, system failure, hardware malfunction, ransomware attacks, natural disasters, cyber incidents, human error, and other operational risks.
Backups may include databases, application data, financial records, membership information, donor records, digital certificates, project documentation, system configurations, email records, cloud storage, and other critical organizational assets.
Backup copies shall, where reasonably practicable, be encrypted, securely stored, periodically tested, and protected through appropriate physical and logical security controls.
The Foundation shall maintain disaster recovery and business restoration procedures designed to restore critical operations within reasonable timeframes following significant disruptions.
Information Security Incident Management
Every actual, suspected, or potential information security incident shall be reported promptly through the Foundation’s authorized incident reporting procedures.
Information security incidents may include unauthorized system access, attempted cyber intrusions, malware infections, ransomware attacks, phishing attempts, data breaches, credential compromise, denial-of-service attacks, unauthorized disclosure of confidential information, theft of organizational devices, insider misuse, unauthorized modifications of information, or any other event affecting the confidentiality, integrity, or availability of organizational information.
Upon identification of a security incident, the Foundation may undertake appropriate actions including incident assessment, containment, forensic investigation, evidence preservation, recovery procedures, communication with affected stakeholders, regulatory notifications where legally required, implementation of corrective actions, and post-incident review to strengthen future security controls.
Vulnerability Management
The Foundation shall continuously monitor and assess its digital infrastructure for security weaknesses that may expose organizational information or systems to cyber threats.
Security activities may include vulnerability assessments, penetration testing, software patch management, configuration reviews, code analysis, infrastructure monitoring, security scanning, risk assessments, dependency management, and continuous evaluation of emerging cybersecurity threats.
Identified vulnerabilities shall be assessed according to their severity, operational impact, exploitation risk, and organizational priorities, with appropriate remediation measures implemented within reasonable timeframes.
Malware Protection
Just Help Me Foundation shall implement appropriate safeguards to reduce the risk of malware, ransomware, spyware, trojans, worms, viruses, botnets, malicious scripts, and other forms of malicious software affecting organizational systems.
Protective measures may include endpoint protection software, antivirus solutions, behavioral detection technologies, application control, secure software updates, attachment scanning, web filtering, email security controls, threat intelligence, and continuous monitoring.
Users shall not intentionally install unauthorized software, disable security protections, connect untrusted storage devices, or execute suspicious files that may compromise organizational security.
Security Monitoring
The Foundation may implement continuous monitoring of its networks, servers, cloud infrastructure, applications, databases, communication systems, APIs, payment platforms, and other digital resources to detect suspicious activities, unauthorized access attempts, abnormal system behavior, cybersecurity threats, operational failures, and security incidents.
Monitoring activities shall be conducted for legitimate organizational purposes including cybersecurity, fraud prevention, legal compliance, system maintenance, performance optimization, incident response, and protection of organizational assets.
Monitoring shall be performed in accordance with applicable laws, privacy obligations, and recognized information security practices.
Logging and Audit Trails
Appropriate audit logs may be maintained for critical organizational systems in order to support accountability, security monitoring, forensic investigations, operational troubleshooting, regulatory compliance, and internal governance.
Audit logs may include user authentication records, administrative activities, access events, security alerts, system changes, financial transactions, database activities, application events, network events, and other operational records relevant to the protection of organizational information.
Access to audit logs shall be restricted to authorized personnel and protected against unauthorized alteration, deletion, disclosure, or misuse.
Business Continuity
Just Help Me Foundation recognizes the importance of maintaining essential charitable operations during emergencies and significant operational disruptions.
The Foundation may establish business continuity procedures designed to maintain or restore critical services including membership management, donor services, payment processing, communication systems, volunteer coordination, financial administration, project management, digital verification services, and other essential organizational functions.
Business continuity planning may include emergency response procedures, alternate communication methods, backup infrastructure, redundancy mechanisms, remote working capabilities, supplier continuity planning, periodic testing, and continuous improvement activities.
Third-Party Information Security
Where organizational information is processed, stored, transmitted, or accessed by third-party service providers, technology vendors, payment processors, cloud service providers, consultants, contractors, or other external organizations, the Foundation shall make reasonable efforts to ensure that appropriate contractual, technical, administrative, and organizational security safeguards are maintained.
Third-party providers may be required to comply with confidentiality obligations, information security requirements, applicable legal standards, incident reporting obligations, audit provisions, and other contractual controls designed to protect Foundation information.
The Foundation reserves the right to review, monitor, or assess third-party security practices where appropriate and reasonably necessary.
Security Awareness and Training
Information security depends upon the awareness, knowledge, and responsible conduct of every individual associated with the Foundation.
Accordingly, Just Help Me Foundation may provide periodic information security awareness programs, cybersecurity training, phishing awareness exercises, privacy education, policy briefings, incident response guidance, secure technology practices, and compliance training for trustees, directors, employees, volunteers, consultants, contractors, interns, and other authorized personnel.
Training programs may be updated periodically to reflect evolving cybersecurity threats, technological developments, legal requirements, organizational policies, and internationally recognized best practices.
Every authorized user shares responsibility for protecting organizational information by complying with security procedures, reporting suspicious activities promptly, safeguarding authentication credentials, maintaining confidentiality, and supporting the Foundation’s commitment to secure and responsible information management.
Relationship with Other Policies
This Universal Information Security Policy shall be interpreted together with the Foundation’s Universal Privacy Policy, Universal Data Protection Policy, Universal Cookie Policy, Universal Terms and Conditions, Universal Disclaimer Policy, Universal Donation Policy, Universal Refund and Cancellation Policy, Universal Membership Policy, Universal Grievance Redressal Policy, Acceptable Use Policy, Records Retention Policy, Business Continuity Policy, Employment Policy, Volunteer Policy, Vendor Management Policy, and every other officially published policy governing the Foundation’s operations.
Where any matter concerning cybersecurity, confidentiality, privacy, data governance, digital infrastructure, or information protection is specifically governed by another officially published policy, that policy shall prevail with respect to the relevant subject matter to the extent of any inconsistency.
Policy Amendments
Just Help Me Foundation reserves the absolute and continuing right to amend, revise, update, replace, modify, interpret, suspend, or withdraw this Universal Information Security Policy at any time whenever such action is considered necessary to comply with applicable laws, judicial decisions, governmental regulations, cybersecurity threats, technological advancements, organizational restructuring, operational improvements, internationally recognized security standards, or any other legitimate governance requirement.
The latest version of this Universal Information Security Policy shall always be published on the Foundation’s official digital platforms. Continued access to or use of any official website, mobile application, membership portal, donation platform, payment gateway, software platform, cloud service, employment portal, volunteer portal, API, or any other official digital service following publication of an updated version shall constitute acceptance of the revised Policy.
Governing Law
This Universal Information Security Policy shall be governed by, interpreted, and enforced in accordance with the laws applicable to the jurisdiction in which Just Help Me Foundation is legally established and operates, together with all applicable national and international legal requirements relating to information security, cybersecurity, electronic communications, privacy, data protection, electronic records, consumer protection, nonprofit governance, financial compliance, intellectual property, and digital technologies.
Nothing contained in this Policy shall restrict or limit the Foundation’s right to comply with lawful governmental requests, judicial orders, regulatory directives, cybersecurity incident reporting obligations, law enforcement investigations, or other legally binding requirements.
Dispute Resolution
Any dispute, complaint, controversy, or claim arising out of or relating to this Universal Information Security Policy, cybersecurity incidents, unauthorized access, digital platform usage, information protection measures, or interpretation of this Policy shall first be addressed through the Foundation’s official grievance and dispute resolution procedures.
Where a matter cannot reasonably be resolved through internal procedures, either party may refer the matter to the competent court, tribunal, arbitration authority, mediator, or any other legally authorized dispute resolution forum having jurisdiction under applicable law.
Nothing contained in this Policy shall prevent either party from seeking interim relief, emergency legal protection, injunctive orders, preservation of digital evidence, or any other remedy available under applicable law.
Severability
If any provision, clause, paragraph, sentence, or part of this Universal Information Security Policy is declared invalid, unlawful, void, or unenforceable by any court of competent jurisdiction or other legally authorized authority, such determination shall not affect the legality, validity, or enforceability of the remaining provisions.
The remaining provisions shall continue in full force and effect to the maximum extent permitted by applicable law, and the invalid provision shall, wherever reasonably possible, be interpreted in a manner that most closely reflects the original intent of the Foundation while remaining legally enforceable.
Entire Agreement
This Universal Information Security Policy forms an integral part of the Foundation’s legal, governance, cybersecurity, privacy, compliance, and risk management framework. It shall be read together with the Foundation’s Universal Privacy Policy, Universal Data Protection Policy, Universal Cookie Policy, Universal Terms and Conditions, Universal Disclaimer Policy, Universal Donation Policy, Universal Refund and Cancellation Policy, Universal Membership Policy, Universal Grievance Redressal Policy, Acceptable Use Policy, Records Retention Policy, Business Continuity Policy, Disaster Recovery Policy, Employment Policy, Volunteer Policy, Vendor Management Policy, and every other officially published policy governing the operations of Just Help Me Foundation.
Where any issue concerning cybersecurity, confidentiality, digital infrastructure, information governance, or information assets is specifically governed by another officially published policy, that policy shall prevail with respect to the relevant subject matter to the extent of any inconsistency.
Contact Information
Questions, security concerns, suspected cybersecurity incidents, vulnerability disclosures, legal notices, compliance communications, requests relating to information security, breach notifications, or any other correspondence concerning this Universal Information Security Policy should be submitted only through the official communication channels published on the authorized digital platforms of Just Help Me Foundation.
Users, members, employees, volunteers, technology partners, contractors, vendors, and other stakeholders are advised to communicate exclusively through officially published email addresses, support systems, security reporting channels, grievance portals, telephone numbers, or authorized Foundation offices to ensure the confidentiality, authenticity, integrity, and secure handling of all information security matters.
No Waiver
The failure or delay of Just Help Me Foundation to exercise or enforce any right, authority, remedy, or provision contained in this Universal Information Security Policy shall not constitute a waiver of such right or remedy.
Any waiver shall be valid only if expressly made in writing by an authorized representative of the Foundation. A waiver relating to one specific incident shall not constitute a continuing waiver or a waiver of any future breach or any other provision contained in this Policy.
Survival
The provisions of this Universal Information Security Policy relating to confidentiality, cybersecurity, information protection, intellectual property, audit rights, incident reporting, regulatory compliance, dispute resolution, governing law, limitation of liability, record retention, access control, monitoring, and every other provision which by its nature is intended to survive shall remain valid and enforceable even after termination of employment, volunteer service, membership, contractual engagement, partnership, closure of user accounts, discontinuation of digital services, deletion of information where legally permissible, or cessation of any relationship with Just Help Me Foundation.
Final Legal Declaration
By accessing, browsing, registering, creating an account, applying for membership, volunteering, making donations, submitting applications, participating in Foundation programs, communicating with the Foundation, using digital services, accessing online portals, utilizing payment gateways, operating administrative systems, accessing cloud services, using APIs, submitting information, or otherwise interacting with any official website, domain, subdomain, mobile application, online portal, software platform, payment gateway, cloud-based service, API, membership platform, employment portal, volunteer portal, award portal, digital verification system, communication platform, or any future digital service owned, operated, managed, licensed, or officially authorized by Just Help Me Foundation (JHMF), you acknowledge that you have carefully read, fully understood, and voluntarily accepted this Universal Information Security Policy in its entirety.
This Universal Information Security Policy shall apply uniformly to all existing and future official websites, domains, subdomains, software applications, cloud services, payment systems, membership platforms, volunteer systems, employment portals, award portals, databases, APIs, communication platforms, digital verification services, artificial intelligence systems, cybersecurity infrastructure, information assets, and every other official digital property administered by Just Help Me Foundation.
Your continued access to or use of any official digital platform after publication of an updated version of this Policy shall constitute your continued acceptance of the revised provisions.
Commitment to Information Security
Just Help Me Foundation reaffirms its unwavering commitment to maintaining the highest standards of information security, cybersecurity governance, digital resilience, operational continuity, legal compliance, ethical responsibility, and stakeholder trust. The Foundation shall continue to strengthen its security framework through continuous monitoring, periodic risk assessments, adoption of internationally recognized best practices, regular policy reviews, technological innovation, security awareness initiatives, and ongoing improvement of administrative, technical, organizational, and physical safeguards to protect its information assets and the interests of all stakeholders.