We use reasonable and appropriate organizational, physical and technical safeguards designed to protect personal data against accidental loss, unauthorized access, disclosure, alteration, misuse or destruction. Measures may include role-based access, password controls, staff confidentiality, secure transmission, backups, monitoring, vendor review and incident-response procedures.