Version 2.0. Last reviewed: September 2026. Next scheduled review: September 2027.

1.0 Purpose

This Information Security Policy (ISP) defines the minimum information security requirements for Very Good Plugins, LLC (“Company”), the developer and maintainer of WP Fusion, a WordPress plugin that connects WordPress websites to CRM and marketing automation platforms.

WP Fusion is self-hosted software. It runs on the customer’s own WordPress website and sends data from that site directly to the customer’s CRM. The Company does not receive, store or process the customer’s CRM data or the personal data of the customer’s website users. This policy covers the security of the plugin itself, the Company’s own systems, and the limited customer data the Company does hold (account, licence, billing and support records).

This policy is the umbrella document for the Company’s security practices. It sets out how the Company will:

  • Protect the confidentiality, integrity and availability of customer account data, source code and infrastructure
  • Build and release the plugin securely, and fix vulnerabilities quickly when they are found
  • Detect, respond to and notify customers about security incidents
  • Keep team devices and accounts secure in a fully remote organisation
  • Comply with GDPR, CCPA and other applicable data protection laws

2.0 Authority

Very Good Plugins, LLC is the sole authority for the development, maintenance and security of WP Fusion. This policy is approved by the Founder and applies to all employees, contractors and third-party service providers working on the Company’s behalf.

3.0 Scope

This policy covers:

  • The WP Fusion plugin (Lite and Pro) and its add-ons
  • The wpfusion.com website, licence and update servers, and customer account portal
  • Customer account, licence, billing and support records held by the Company
  • Support systems and support interactions, including any access granted to customer sites
  • Development and testing environments and source code repositories
  • All devices and accounts used by team members to perform Company work

4.0 Information Statement

4.1 Organizational Security

4.1.1 Security Roles and Responsibilities

Founder (Security and Data Protection Lead). Owns this policy and the Company’s security strategy. Approves security procedures, allocates resources, leads incident response, and acts as the designated data protection contact.

Lead Developer. Responsible for secure development practices, code security review, vulnerability triage and remediation, dependency monitoring, and tracking security advisories for WordPress and integrated platforms.

Support Team. Responsible for handling customer data securely during support interactions, following the customer site access procedure in section 4.13, and escalating suspected security issues to the Founder or Lead Developer.

4.1.2 Team Structure and Locations

The Company is a small, fully remote organisation with no office premises. Team members and contractors currently work from Germany, Romania and the Philippines. Some team members are engaged through staffing partners and are bound by this policy and by confidentiality agreements in the same way as direct staff. Production infrastructure is hosted in the United States (see section 4.8.1).

4.2 Plugin Security Architecture

4.2.1 Secure Development Practices

  • All code is peer reviewed before release, including automated and human review of each pull request
  • Security implications are reviewed for each release
  • WordPress coding standards and the WordPress security guidelines are followed
  • All user input is validated and sanitized
  • Database queries use prepared statements to prevent SQL injection
  • Output is escaped to prevent cross-site scripting (XSS)
  • WordPress nonces and capability checks protect against cross-site request forgery (CSRF) and privilege escalation
  • Development practices reference the OWASP Top 10

4.2.2 API Security

  • All API communication between the plugin and CRM platforms uses TLS encryption
  • OAuth 2.0 is used where the CRM supports it
  • Rate limiting is applied to Company APIs to prevent abuse
  • Error messages do not expose credentials or other sensitive information

4.3 Data Classification and Handling

4.3.1 Data Categories

Highly sensitive:

  • Customer CRM API keys and credentials. These are stored only in the customer’s own WordPress database and never on Company servers.
  • Customer personal information held by the Company (name, email, billing address)
  • Payment information, which is handled by PCI DSS compliant payment processors and never stored on Company servers
  • Licence keys
  • Credentials temporarily shared with the Company for support purposes

Sensitive:

  • OAuth authorization records (site URL, customer ID, authorization dates)
  • Support ticket content
  • Usage and licence activation data

Public: documentation, marketing content, and the plugin changelog.

4.3.2 Data Handling Requirements

  • Customer CRM credentials are never stored on Company servers. They remain exclusively in the customer’s WordPress database.
  • OAuth authorizations are logged for security auditing (site URL, customer ID, dates). Access tokens are not stored by the Company.
  • No customer CRM data is stored on Company servers. All processing happens on the customer’s WordPress site.
  • Where a support request requires credentials, they must be shared through a secure, temporary method (such as a one-time secret link) and not in plain email or chat. Credentials are deleted from support systems once the ticket is resolved.
  • Customer data in support tickets is retained only as long as necessary to provide support.

4.4 Access Control

4.4.1 Administrative Access

  • Multi-factor authentication (MFA) is required on all administrative accounts and on all systems holding customer data
  • Access to production systems is limited to authorised personnel who need it for their role
  • The principle of least privilege is applied to all accounts
  • Access rights are reviewed quarterly and on any change of role
  • Server administration uses key-based authentication. Password login to servers is disabled.
  • Access is identity-based rather than network-based. Because the Company has no internal office network (section 4.7), systems are accessed directly over encrypted connections with MFA rather than through a VPN.

4.4.2 Customer Access

  • Customer accounts are protected by strong password requirements
  • A valid licence is verified before plugin updates are delivered
  • Account recovery requires identity verification

4.5 Vulnerability Management

4.5.1 Security Monitoring and Disclosure

The Company participates in external vulnerability disclosure programs so that security researchers have a clear, coordinated way to report issues:

  • Patchstack. WP Fusion participates in the Patchstack Vulnerability Disclosure Program, which provides continuous monitoring, triage and coordinated disclosure. Public profile: patchstack.com/database/wordpress/plugin/wp-fusion-lite
  • Wordfence. The Company is a verified vendor with Wordfence Intelligence and receives vulnerability reports through the Wordfence vendor portal.

Disclosure channels are monitored by at least two team members so that reports are acknowledged within the timeframes in Appendix B even when one person is unavailable.

Additional monitoring:

  • Automated vulnerability scanning of Company systems (weekly) and manual review (quarterly)
  • Daily monitoring of WordPress core and ecosystem security advisories
  • Dependency scanning for third-party libraries, with automated alerts for known vulnerabilities

4.5.2 Vulnerability Response

  • Reported vulnerabilities are acknowledged and triaged according to the severity levels in Appendix B
  • Critical vulnerabilities trigger an immediate patch release
  • Patches are coordinated with the reporting program before public disclosure
  • Security fixes are recorded in the public changelog
  • CVE identifiers are obtained for significant vulnerabilities, usually through the reporting program

4.6 Third-Party Security

4.6.1 Integration Security

  • Secure configuration guidance is documented for each CRM integration
  • API and authentication changes from integrated platforms are monitored

4.6.2 Service Providers

Hosting providers must hold SOC 2 or equivalent certification, and payment processors must be PCI DSS compliant. The Company’s main service providers are:

ProviderPurposeLocationAttestations
VultrHosting for wpfusion.com, licence and update serversNew Jersey, USASOC 2 Type II, ISO 27001, PCI DSS
CloudflareDNS, CDN, web application firewall, DDoS protectionGlobalSOC 2 Type II, ISO 27001, PCI DSS
GitHubSource code hosting and code reviewUSASOC 2 Type II, ISO 27001
PatchstackVulnerability disclosure and monitoringEstonian/a
WordfenceVulnerability disclosure and threat intelligenceUSAn/a
Payment processorsCard and payment processingVariesPCI DSS

AI-assisted tools may be used by the team to help draft support replies and review code. Only providers whose business terms exclude training on submitted data are used, and customer credentials must never be submitted to them.

4.6.3 Certifications

The Company does not currently hold company-level security certifications such as SOC 2 or ISO 27001. It relies on the attestations of its infrastructure providers listed above, on external vulnerability disclosure programs, and on the controls in this policy.

4.7 Remote Working and Endpoint Security

The Company has no office premises and no internal corporate network. All work is performed remotely, and this policy is the Company’s remote working policy. It applies to every team member and every device used for Company work, regardless of location.

4.7.1 Devices

  • Devices used for Company work must have full-disk encryption enabled
  • Devices must run an operating system version that still receives security updates from its vendor
  • Automatic operating system and browser security updates must be enabled. Security patches must be applied within 14 days of release, and within 72 hours for actively exploited vulnerabilities.
  • Endpoint protection (built-in or third-party anti-malware) must be active
  • Screens must lock automatically after no more than 10 minutes of inactivity
  • Devices must not be shared with people outside the Company
  • Lost or stolen devices must be reported to the Founder immediately so that sessions can be revoked and credentials rotated

4.7.2 Accounts and Networks

  • A password manager must be used for Company credentials, with unique passwords for every account
  • MFA must be enabled on every Company account that supports it
  • Company systems are only accessed over encrypted connections (HTTPS, SSH). Because there is no internal network to protect, a VPN is not required.
  • Home network equipment must not use default administrator passwords

4.8 Business Continuity and Data Resilience

4.8.1 Infrastructure and Hosting

  • Production systems are hosted with Vultr in New Jersey, USA (SOC 2 Type II, ISO 27001, PCI DSS)
  • Traffic to wpfusion.com passes through Cloudflare for DDoS protection and web application firewall (WAF) filtering
  • Intrusion detection and prevention and 24/7 monitoring are provided at the hosting and network layer
  • Vulnerability scanning of Company systems runs weekly (automated), with manual review quarterly
  • Endpoint protection is active on all servers and team devices
  • All data in transit is encrypted with TLS
  • Sensitive data at rest is encrypted

4.8.2 Backup and Recovery

  • Daily automated backups of critical systems
  • Backups are stored in a geographically separate location from production
  • 30-day retention for daily backups and 90-day retention for monthly archives
  • Source code is held in version control with redundant copies
  • Recovery Time Objective (RTO): 4 hours for critical systems
  • Recovery Point Objective (RPO): 24 hours
  • Backup restoration is tested at least annually

4.8.3 Availability

  • Uptime target of 99.9% for wpfusion.com
  • Static assets and plugin downloads are served through a CDN
  • Uptime monitoring with automated alerting
  • If licence or update servers are unavailable, installed copies of WP Fusion continue to operate normally on customer sites

4.8.4 Audit Logging and Monitoring

  • Administrative access to Company systems is logged and retained for 90 days
  • OAuth authorizations are logged (site URL, customer ID, creation date, last authorization date)
  • API access and plugin update requests are logged for security analysis
  • Access to logs is restricted to authorised personnel
  • Error logs are monitored, with automated alerts for suspicious activity

4.8.5 Incident Response and Breach Notification

Incident response.

  • Response to critical incidents begins within 24 hours of detection
  • The Founder leads incident response, with defined escalation to the Lead Developer
  • Affected credentials and sessions are revoked and rotated as a first containment step
  • Every security incident is followed by a written post-incident review
  • The incident response plan is reviewed annually as part of the policy review

Breach notification.

  • If an incident affects personal data held by the Company, affected customers are notified without undue delay and no later than 72 hours after the incident is confirmed, so that customers acting as data controllers can meet their own obligations under GDPR Article 33
  • Where required, the relevant supervisory authority is notified within 72 hours
  • Notifications describe what happened, what data was affected, what the Company has done, and what the customer should do
  • Plugin vulnerabilities are handled and communicated under Appendix B

Business continuity.

  • Documented procedures for restoring services from backup
  • Alternative communication channels for the team and for customers
  • Vendor contact list maintained
  • Critical functions (releases, support, infrastructure access) are covered by more than one team member

4.8.6 Vendor Management

  • Due diligence is performed before engaging any vendor that will hold Company or customer data
  • Security and confidentiality requirements are included in vendor contracts where possible
  • Critical vendors’ security attestations are reviewed annually

4.9 Security Awareness and Training

  • All team members complete security, phishing awareness and privacy training during onboarding and at least annually
  • Developers receive secure coding training and review guidance
  • Support staff are trained on secure handling of customer credentials and the procedure in section 4.13
  • Security procedures are documented and available to the whole team

4.10 Physical Security

  • Company work is performed on encrypted devices with endpoint protection (section 4.7)
  • Screens lock automatically after 10 minutes of inactivity
  • Clean desk practice for any sensitive information, and locked storage for any physical media containing sensitive data
  • Hardware containing sensitive data is securely wiped or destroyed using NIST-approved methods before disposal
  • Data center physical security is provided by Vultr, including 24/7 on-site security, biometric access controls, CCTV, environmental monitoring, and redundant power and network

4.11 Compliance with Data Protection Laws

4.11.1 Regulatory Compliance

  • Compliance with the General Data Protection Regulation (GDPR)
  • Compliance with the California Consumer Privacy Act (CCPA)
  • Adherence to other data protection laws applicable to the Company’s customers
  • Regulatory requirements are reviewed annually as part of the policy review

4.11.2 Data Protection Measures

Administrative safeguards.

  • The Founder is the designated data protection contact
  • Privacy impact is assessed before new systems or vendors handle personal data
  • Data processing agreements are in place with vendors that process personal data on the Company’s behalf
  • All team members and contractors sign confidentiality agreements
  • Privacy training for all team members (section 4.9)

Technical safeguards.

  • Encryption of personal data in transit and at rest
  • Access controls based on least privilege
  • Regular vulnerability scanning and external vulnerability disclosure programs

Physical safeguards. See section 4.10.

International access. Customer account and support data is hosted in the USA and may be accessed by team members in the EU and the Philippines for the purpose of providing support. See the Privacy Policy for details.

4.12 Workforce Security

4.12.1 Onboarding

  • Identity and prior work references are verified before any access is granted
  • Every new team member signs a confidentiality agreement and acknowledges this policy
  • Accounts are created with MFA and with the minimum access needed for the role
  • Security, phishing awareness and privacy training is completed within the first 30 days

4.12.2 Background Checks

Given the Company’s size and fully remote, international team, formal criminal or credit background checks are not performed. The Company relies on the compensating controls in this policy: reference and identity verification, confidentiality agreements, least privilege access, MFA, and quarterly access reviews. Team members have no access to customer websites or CRM systems unless the customer grants it for a specific support case (section 4.13).

4.12.3 Offboarding

  • All access is revoked within 24 hours of a team member’s departure
  • Any shared credentials the team member had access to are rotated
  • Company data is removed from personal devices

4.13 Customer Site Access for Support

Most support requests are resolved using the plugin’s activity logs, screenshots or a screen share, without any access to the customer’s website. Access is only requested when an issue cannot be reproduced or diagnosed any other way, for example a sync problem that only occurs on the customer’s site or a conflict with another plugin or theme.

When access is needed:

  • The customer creates a temporary WordPress user for the Company. WP Fusion’s settings require the Administrator role.
  • A staging copy of the site is preferred over production, ideally with personal data removed
  • The Company never requests CRM login credentials, or hosting, server or database access
  • Credentials are shared through a secure, temporary method (section 4.3.2)
  • Access is used only for the specific support case, and changes made are documented in the support ticket
  • The customer deletes the account when the ticket is resolved
  • The Company will sign the customer’s confidentiality agreement before access is granted, on request

4.14 Software Updates and Licence Expiry

  • Plugin updates are delivered through the WordPress dashboard to sites with an active licence, as described in the Terms and Conditions
  • If a licence expires, the plugin continues to work
  • If a critical or high severity vulnerability (Appendix B) affects a version used by a customer whose licence has expired, the Company will notify the customer by email and provide the patched version on request

5.0 Compliance

All team members, contractors and third-party service providers working on the Company’s behalf must comply with this policy. Non-compliance may result in disciplinary action, up to and including termination of employment or contract.

5.1 Exceptions

Exceptions to this policy must be requested in writing to the Founder, with a business justification and proposed compensating controls. Approved exceptions are recorded and reviewed at the next policy review.

5.2 Policy Review

This policy is reviewed at least annually, and whenever there is a significant change to business operations, infrastructure, regulatory requirements or the threat environment.

6.0 Definitions

TermDefinition
APIApplication Programming Interface. The connection method between WP Fusion and CRM platforms.
CRMCustomer Relationship Management system
MFAMulti-Factor Authentication
PIIPersonally Identifiable Information
TLSTransport Layer Security, the encryption protocol used for data in transit
WordPress nonceA one-time token WordPress uses to protect against CSRF
OAuthOpen Authorization, a standard for granting access without sharing passwords
PatchstackThird-party vulnerability disclosure, monitoring and coordination service
Wordfence IntelligenceThird-party vulnerability database and disclosure program for WordPress

7.0 Contact Information

Security questions about this policy:

Very Good Plugins, LLC
16192 Coastal Highway, Lewes, Delaware 19958, USA
Email: support [at] wpfusion.com
Support: wpfusion.com/contact

Reporting a vulnerability. Please report security vulnerabilities through our disclosure program rather than public support channels:

8.0 Revision History

DateDescription of changeApproved by
August 2025Initial policyFounder
September 2026Annual review. Updated roles and team locations. Added remote working and endpoint security (4.7), workforce security (4.12), customer site access for support (4.13), software updates and licence expiry (4.14), and certifications (4.6.3). Added 72-hour breach notification (4.8.5). Added Wordfence as a disclosure channel. Updated service provider list.Founder

9.0 Related Documents

10.0 Appendix A: CRM Integration Security Matrix

WP Fusion integrates with 60+ CRM and marketing automation platforms. The Company maintains a matrix documenting, for each integration, the authentication method, encryption and transport, API rate limits and any integration-specific security considerations. The matrix is available to customers on request.

11.0 Appendix B: Vulnerability Response Procedures

11.1 Severity Classification

  • Critical: remote code execution, authentication bypass, unauthenticated privilege escalation, data breach
  • High: SQL injection, authenticated privilege escalation, XSS with significant impact
  • Medium: limited XSS, information disclosure, CSRF
  • Low: minor information leakage, hardening issues

11.2 Response Times

  • Critical: immediate response, patch released within 24 hours of validation
  • High: response within 24 hours, patch within 48 hours
  • Medium: response within 48 hours, patch within 7 days
  • Low: addressed in the next regular release

11.3 Communication

  • Disclosure timing is coordinated with the reporting program (Patchstack or Wordfence)
  • Patches are released before vulnerability details are made public
  • Security fixes are listed in the public changelog
  • Affected customers are notified by email for critical and high severity issues
  • Updates are pushed through WordPress.org (Lite) and the WP Fusion update server (Pro)