DOCTRINE

Security Posture

Security is a structural requirement, not a feature. This document defines our security stance, practices, and controls.

Effective:2024-01-01

Security Axiom

Security is not a checkbox. It is built into architecture, processes, and culture. Convenience does not override security. If secure implementation is not possible, the feature does not ship.

Security Principles

Foundational principles governing all security decisions.

Defense in Depth

Multiple layers of security controls. No single point of failure in security architecture.

Least Privilege

Access granted only as needed for role function. No standing privileges.

Zero Trust

No implicit trust based on network location or prior authentication.

Audit Everything

All access and changes logged. Audit trails are immutable.

Data Classification & Handling

How different data types are classified and protected.

CategoryClassificationHandling
Client DataConfidentialEncrypted at rest and in transit. Access logged. Retained per agreement.
CredentialsSecretNever stored in code. Managed through secrets management. Rotated regularly.
PIIRestrictedMinimized collection. Encrypted. Access requires justification.
AnalyticsInternalAggregated where possible. No PII in analytics systems.

Access Controls

System access by role.

Production Infrastructure

DevOps only, with approval workflow

Client CRM (GoHighLevel)

Role-based, client-specific

Source Code

Engineering team, via pull request

Financial Systems

Finance role only

Client Communications

Designated team members per engagement

Incident Response

How security incidents are handled.

1
Detection

Automated monitoring, logging, and alerting on anomalies.

2
Containment

Isolate affected systems. Prevent lateral movement.

3
Assessment

Determine scope, impact, and root cause.

4
Notification

Inform affected parties per regulatory and contractual requirements.

5
Remediation

Fix vulnerability. Restore from known-good state if needed.

6
Review

Document lessons learned. Update controls.

Reporting Security Issues

Security vulnerabilities should be reported through secure channels. Do not disclose vulnerabilities publicly before remediation. Responsible disclosure is expected and appreciated.

/company = authority + intelligence