Security

Remote Work Policy

Built on a design fact: our systems do not trust the network they are accessed from. From inside or outside the office, the requirements are the same — what this policy adds is conduct at the endpoint.

Version 1.0 — effective September 1, 2026.

1. The workstation

  • Antivirus and firewall active and updating, as on any company workstation.
  • Operating system session with a password and screen locked when away — homes have visitors and open windows too.
  • Work only on equipment under these controls — not on borrowed or shared machines.

2. The credentials

  • Passwords live in the encrypted password vault — never on paper, in a text file, in chat or in e-mail.
  • A credential typed on a machine that is not yours is a credential rotated on return.

3. The network

A trusted network — the password-protected one at home, or the phone's own hotspot. Open third-party Wi-Fi is avoided; when unavoidable, the systems' mandatory encrypted channel is what protects, and nothing beyond the systems is accessed through it.

4. The data

  • Customer data is not copied to the workstation beyond what support requires, and what was copied is deleted on completion — the source of truth is the server.
  • Screens with customer data are not displayed in public places.
  • A support call on speakerphone in a public place is leakage by voice.

5. Incidents

Lost or stolen equipment, suspected unauthorized access, exposed credential: report immediately — the Incident Response Plan applies, and the first containment does not wait until the next day.

Version 1.0 — September 1, 2026.