Skip to content

IT Security Policy TOC

All employees and contractors are required to read and comply with all IT security policies in their entirety. Please start by reading Information Security Policy.

When in doubt about any security policy or procedure, please consult the full policy documentation or contact the Head of Platform or CISO.

This executive summary serves as a quick reference guide and highlights key points, but does not replace the need to understand the complete policies.

These points represent critical security practices that impact daily work for all employees.

  • Complete annual security awareness training
  • Report suspected security incidents immediately to the Head of Platform
  • Never share your credentials with anyone
  • Protect all information assets regardless of location
  • All data must be classified as Internal, Public, Customer, Confidential, or Restricted
  • No customer data should ever be stored on employee laptops or personal devices
  • Use only approved cloud services (Google Drive, S3, Fly.io) for company data
  • Confidential data requires encryption when transmitted
  • Register personal devices used for work with IT
  • Install operating system updates at least weekly
  • Use company-approved antivirus software
  • Enable two-factor authentication for all company resources
  • Lock devices when unattended (auto-lock after 5 minutes)
  • Use secure WPA2/WPA3 encrypted home Wi-Fi
  • VPN required for accessing customer data
  • Report lost or stolen devices immediately
  • Store work documents in approved cloud storage, not locally

These points cover the technical aspects of our security framework, particularly relevant for IT staff and developers.

  • All material vendors must be evaluated for SOC 2 compliance
  • IT personnel must maintain a list of vendors with access to financial/confidential data
  • Service level agreements must be documented clearly
  • Performance issues must be addressed in writing
  • Recovery Time Objective (RTO): 24 hours
  • Emergency Response Team has defined roles and backups
  • Annual disaster recovery testing required
  • Incident response includes defined communication protocols
  • Annual formal risk assessment required
  • Critical assets must be identified and documented
  • Threats and vulnerabilities must be reviewed
  • Results must inform updates to other security policies
  • TLS certificates managed by Fly.io/Let’s Encrypt
  • Laravel APP_KEY rotated annually
  • Keys stored in Doppler with restricted access
  • Emergency key rotation procedures defined
  • Endpoint protection software required
  • Quarterly vulnerability scanning required
  • Annual penetration testing required
  • Critical/high risk vulnerabilities must be remediated immediately
  • All changes require Git pull requests and code review
  • Infrastructure must be managed as code
  • Testing in staging required before production deployment
  • Change logs must be maintained in chat
  • Code repositories, customer files, and databases require specific backup procedures
  • Annual backup restoration testing required
  • Incident response process defined for data loss
  • Database snapshots retained for 30 days
  • Production VMs must run Ubuntu LTS
  • Security patches applied every 14 days
  • System monitoring and audit logging required
  • Default deny all inbound connections

Internal & Confidential: This page is only available in the internal handbook and contains confidential information.