IT Security Policy TOC
All employees and contractors are required to read and comply with all IT security policies in their entirety. Please start by reading Information Security Policy.
When in doubt about any security policy or procedure, please consult the full policy documentation or contact the Head of Platform or CISO.
About This Summary
Section titled “About This Summary”This executive summary serves as a quick reference guide and highlights key points, but does not replace the need to understand the complete policies.
Core Security Responsibilities
Section titled “Core Security Responsibilities”These points represent critical security practices that impact daily work for all employees.
Information Security Policy
Section titled “Information Security Policy”- Complete annual security awareness training
- Report suspected security incidents immediately to the Head of Platform
- Never share your credentials with anyone
- Protect all information assets regardless of location
Data Security & Classification
Section titled “Data Security & Classification”- All data must be classified as Internal, Public, Customer, Confidential, or Restricted
- No customer data should ever be stored on employee laptops or personal devices
- Use only approved cloud services (Google Drive, S3, Fly.io) for company data
- Confidential data requires encryption when transmitted
Device & Access Security
Section titled “Device & Access Security”- Register personal devices used for work with IT
- Install operating system updates at least weekly
- Use company-approved antivirus software
- Enable two-factor authentication for all company resources
- Lock devices when unattended (auto-lock after 5 minutes)
Remote Work Security
Section titled “Remote Work Security”- Use secure WPA2/WPA3 encrypted home Wi-Fi
- VPN required for accessing customer data
- Report lost or stolen devices immediately
- Store work documents in approved cloud storage, not locally
Technical Implementation Details
Section titled “Technical Implementation Details”These points cover the technical aspects of our security framework, particularly relevant for IT staff and developers.
Vendor Management Policy
Section titled “Vendor Management Policy”- All material vendors must be evaluated for SOC 2 compliance
- IT personnel must maintain a list of vendors with access to financial/confidential data
- Service level agreements must be documented clearly
- Performance issues must be addressed in writing
Business Continuity and Disaster Recovery
Section titled “Business Continuity and Disaster Recovery”- Recovery Time Objective (RTO): 24 hours
- Emergency Response Team has defined roles and backups
- Annual disaster recovery testing required
- Incident response includes defined communication protocols
Risk Assessment Policy
Section titled “Risk Assessment Policy”- Annual formal risk assessment required
- Critical assets must be identified and documented
- Threats and vulnerabilities must be reviewed
- Results must inform updates to other security policies
Encryption Key Management Policy
Section titled “Encryption Key Management Policy”- TLS certificates managed by Fly.io/Let’s Encrypt
- Laravel APP_KEY rotated annually
- Keys stored in Doppler with restricted access
- Emergency key rotation procedures defined
Vulnerability Management Policy
Section titled “Vulnerability Management Policy”- Endpoint protection software required
- Quarterly vulnerability scanning required
- Annual penetration testing required
- Critical/high risk vulnerabilities must be remediated immediately
Configuration Management Policy
Section titled “Configuration Management Policy”- All changes require Git pull requests and code review
- Infrastructure must be managed as code
- Testing in staging required before production deployment
- Change logs must be maintained in chat
Backup Policy
Section titled “Backup Policy”- Code repositories, customer files, and databases require specific backup procedures
- Annual backup restoration testing required
- Incident response process defined for data loss
- Database snapshots retained for 30 days
VM Hardening Policy
Section titled “VM Hardening Policy”- Production VMs must run Ubuntu LTS
- Security patches applied every 14 days
- System monitoring and audit logging required
- Default deny all inbound connections
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
