Trust & Security

Information Security Policy

VectorStack maintains a risk-based information security program designed to protect the confidentiality, integrity, and availability of our systems, services, and information.

Version 1.012a
Effective date July 15, 2026
Policy owner Information Security
Review cycle At least annually

1. Purpose and security objectives

This policy establishes the minimum requirements for safeguarding information and technology resources owned, operated, processed, or managed by VectorStack. It provides a consistent framework for reducing security risk while supporting reliable business operations and responsible innovation.

Our security objectives are to:

  • preserve the confidentiality of information by preventing unauthorized access or disclosure;
  • protect the integrity and accuracy of information and systems;
  • maintain the availability and resilience of services needed by our customers and business;
  • meet applicable legal, regulatory, contractual, and privacy obligations; and
  • identify, assess, treat, and communicate information security risk in a timely manner.

2. Scope

This policy applies to all VectorStack employees, officers, contractors, temporary personnel, consultants, and other authorized users. It covers all information assets and technology used for VectorStack business, regardless of ownership or location, including cloud services, applications, source code, networks, endpoints, credentials, paper records, and third-party systems that process VectorStack or customer information.

All covered individuals must comply with this policy and any related standards, procedures, contractual requirements, and system-specific controls. Where a law or contract imposes a stricter requirement, the stricter requirement applies.

3. Governance and accountability

Executive Management is accountable for information security oversight, allocation of appropriate resources, and acceptance of material residual risk. The Information Security function owns the security program, maintains policies and standards, coordinates risk treatment, and reports significant security matters to management.

System and data owners are responsible for classifying their assets, approving access, defining protection requirements, and ensuring risks are addressed throughout the asset lifecycle. Managers are responsible for enforcing security requirements within their teams. Every workforce member is responsible for protecting company and customer information and promptly reporting suspected security events.

Security policies are reviewed at least annually and following significant changes to the business, technology environment, threat landscape, or applicable obligations. Material changes require approval by the designated management authority.

4. Risk and asset management

VectorStack maintains a risk-based security program. Information security risks must be identified, evaluated, prioritized, assigned to accountable owners, and treated through mitigation, transfer, avoidance, or documented acceptance. Risk assessments are performed periodically and when material changes introduce new exposure.

Information assets must have an identifiable owner and be inventoried at a level appropriate to their sensitivity and operational importance. Assets must be configured, maintained, transferred, and disposed of in a controlled manner. Unauthorized hardware, software, services, and data repositories may not be used for VectorStack business.

5. Identity and access control

Access to systems and information is granted according to business need, least privilege, and separation of duties. Each user must have a unique identity. Shared accounts are prohibited unless technically necessary, formally authorized, and subject to compensating controls and traceability.

  • Access must be approved by an authorized manager or asset owner before it is provisioned.
  • Privileged access must be limited, separately controlled where practicable, and used only for authorized administrative tasks.
  • Multi-factor authentication is required for privileged access, remote access, and systems handling sensitive information where supported.
  • Access rights must be reviewed periodically and promptly adjusted when responsibilities change.
  • Access must be revoked without undue delay when employment, engagement, or business need ends.
  • Service accounts and application credentials must have defined owners, narrowly scoped permissions, controlled use, and periodic review.

6. Password and authentication security

Authentication controls must be proportionate to the sensitivity of the system and the risk of unauthorized access. Passwords and other authentication secrets are confidential and may not be shared, transmitted insecurely, reused across business and personal services, or stored in unapproved locations.

  • Passwords must meet company length and complexity requirements and must not be based on easily guessed or previously compromised values.
  • Company-approved password managers must be used to generate and store unique credentials where available.
  • Default credentials must be changed before a system enters service.
  • Credentials must be changed promptly when compromise is known or suspected. Routine forced changes are used when required by risk, law, contract, or system capability.
  • Authentication secrets, API keys, certificates, and tokens must be stored and distributed using approved secrets-management methods and must never be committed to source control.
  • Systems should implement rate limiting, lockout, or equivalent safeguards against automated authentication attacks where appropriate.

7. Endpoint, mobile, and remote-work security

Endpoints used to access VectorStack resources must be authorized, supported, and configured according to company security standards. Controls must include, as appropriate, full-disk encryption, screen locking, automatic security updates, anti-malware or endpoint detection, host firewall protection, secure configuration, and centralized management.

Users must protect devices from loss, theft, tampering, and unauthorized viewing. Sensitive information may not be stored locally unless required for an approved business purpose and adequately protected. Lost or stolen devices and suspected endpoint compromise must be reported immediately. Remote access must use approved encrypted channels and must not bypass company security controls.

8. Network and infrastructure security

Networks and infrastructure must be designed and operated using layered defenses. Internet-facing services must expose only necessary functionality. Administrative interfaces and sensitive environments must be restricted through access controls, segmentation, secure gateways, or equivalent safeguards.

  • Network devices, operating systems, containers, cloud resources, and services must follow approved secure configuration baselines.
  • Unnecessary ports, protocols, accounts, services, and default features must be disabled or removed.
  • Data transmitted over untrusted networks must use current, industry-accepted encryption.
  • Firewall and security-group rules must be documented, limited to business need, and reviewed periodically.
  • Wireless and remote-access connections must use strong authentication and encryption.
  • Production environments must be appropriately separated from development and testing environments.
  • Infrastructure changes must follow documented change-management and rollback practices proportionate to risk.

9. Data classification, handling, and protection

Information must be classified according to its sensitivity, business value, contractual restrictions, and legal requirements. At minimum, VectorStack distinguishes information intended for public release from internal, confidential, and restricted information. Protection requirements increase with sensitivity.

Collection and use

Only information reasonably necessary for a legitimate, documented business purpose may be collected or processed. Access and use must remain consistent with that purpose, applicable privacy notices, customer commitments, and legal requirements.

Storage and transmission

Confidential and restricted information must be stored only in approved systems. Encryption at rest and in transit must be used where appropriate to the sensitivity and risk. Encryption keys must be protected, access-controlled, rotated where required, and kept separate from encrypted data when practicable.

Retention, backup, and disposal

Information must be retained only for as long as required by business, legal, regulatory, and contractual obligations. Backups must be protected to a level consistent with the source data and tested periodically for recoverability. When retention is no longer required, information and storage media must be securely deleted, destroyed, or rendered unreadable using approved methods.

Data sharing

Information may be shared internally or externally only with authorized recipients and through approved methods. Sensitive data must not be placed in public repositories, personal accounts, consumer file-sharing services, or unapproved artificial intelligence tools.

10. Secure development and change management

Security must be integrated into the design, development, acquisition, deployment, and maintenance of systems. Requirements must be defined according to data sensitivity and risk. Material changes must be reviewed, tested, approved, and deployed in a controlled manner with appropriate recovery plans.

  • Source code must be stored in approved repositories with access controls and change history.
  • Code changes must receive appropriate peer review and automated or manual security testing before production release.
  • Dependencies and third-party components must be selected, tracked, and updated with security risk in mind.
  • Secrets and production data may not be embedded in source code or used in non-production environments without authorization and suitable protection.
  • Applications must validate input, enforce authorization server-side, handle errors safely, and protect against common attack classes.
  • Security findings must be recorded, prioritized by risk, and remediated within defined timeframes.

11. Vulnerability, patch, and threat management

VectorStack monitors relevant sources for vulnerabilities and threats affecting its environment. Systems and software must receive security updates within timeframes proportionate to severity, exposure, exploitability, and business impact. Unsupported technology must be removed, isolated, or covered by a documented risk treatment plan.

Vulnerability assessments, configuration reviews, dependency analysis, or other testing methods are performed as appropriate to system risk. Suspected vulnerabilities must be handled confidentially, validated, prioritized, remediated, and retested. Testing must be authorized in advance and conducted in a manner that protects service availability and customer data.

12. Third-party and cloud security

Vendors and service providers that access VectorStack systems or process sensitive information must undergo security and privacy review proportionate to the risk before use. Contracts must include appropriate confidentiality, security, privacy, incident notification, data-use, return or deletion, and assurance provisions where applicable.

Third-party access must be limited, monitored where appropriate, and removed when no longer required. Critical providers and material changes in their services must be periodically reassessed. Use of a cloud or managed service does not transfer VectorStack's responsibility for securely configuring its accounts, identities, data, and integrations.

13. Logging, monitoring, and acceptable use

Systems must generate and retain security-relevant logs appropriate to their risk, including authentication, privileged activity, administrative changes, and significant security events. Logs must be protected from unauthorized access and alteration, time-synchronized where practicable, and reviewed or alerted on to support timely detection and investigation.

VectorStack resources are provided for authorized business purposes. Users must not circumvent controls, install unapproved software, disclose credentials, access information without authorization, conduct unauthorized security testing, or use company resources for unlawful, abusive, or materially risky activity. Subject to applicable law, VectorStack may monitor and review use of its systems to protect the company, its customers, and its services.

14. Security incident response

Actual or suspected security incidents must be reported immediately through designated channels. VectorStack maintains an incident response process that covers preparation, identification, triage, containment, eradication, recovery, communication, evidence preservation, and post-incident improvement.

  • Incidents are prioritized according to factors such as data sensitivity, scope, operational impact, persistence, and legal or contractual obligations.
  • Only authorized personnel may communicate externally about an incident. Notifications to affected parties, customers, regulators, insurers, or law enforcement are made as required and coordinated with legal and management stakeholders.
  • Evidence and incident records must be preserved with appropriate integrity, confidentiality, and chain-of-custody safeguards.
  • After material incidents, VectorStack documents lessons learned, identifies root causes, and tracks corrective actions to completion.

Report a security concern. If you believe you have identified a security vulnerability or incident affecting VectorStack, contact it@vectorstack.us. Do not access, alter, or retain data that does not belong to you, and do not disrupt our services while conducting security research.

15. Business continuity and recovery

Critical services must have continuity and recovery measures proportionate to their operational importance. Plans must identify dependencies, responsibilities, recovery priorities, communication paths, and procedures for operating through or recovering from disruptive events.

Backups, restoration procedures, failover mechanisms, and continuity plans must be documented and tested periodically as appropriate. Test results and actual disruptions must be reviewed, and identified gaps must be assigned and remediated.

16. Personnel security responsibilities

Security is a shared responsibility. Personnel must complete security and privacy training at onboarding and periodically thereafter. Additional role-based training is required for individuals with privileged access or responsibilities involving sensitive data, software development, infrastructure, finance, or incident response.

  • Personnel must follow policies, protect credentials and devices, keep systems updated, and use only approved tools and services.
  • Suspicious messages, unintended disclosures, lost devices, control failures, and suspected compromise must be reported promptly without fear of retaliation for good-faith reporting.
  • Confidentiality obligations continue after employment or engagement ends.
  • Managers must notify responsible teams promptly of onboarding, role changes, extended leave, and separation so access can be provisioned or removed appropriately.
  • Where lawful and appropriate to the role, background screening and confidentiality agreements may be required.

17. Compliance, exceptions, and enforcement

Compliance with this policy is mandatory. VectorStack may assess compliance through reviews, technical controls, audits, risk assessments, and other reasonable assurance activities. Violations may result in access restriction, corrective action, disciplinary measures up to and including termination of employment or contract, and legal action where appropriate.

Exceptions must be documented, justified by legitimate business or technical need, assessed for risk, approved by the policy owner and accountable management, assigned compensating controls where feasible, and given an expiration or review date. Exceptions do not waive applicable legal, regulatory, or contractual obligations.

This public policy describes VectorStack's security requirements and governance approach. It does not disclose confidential implementation details, create a warranty, or amend a customer agreement. More specific internal standards and procedures may impose additional requirements.

18. Definitions and contact

Information asset
Information, software, infrastructure, device, service, or other resource that has value to VectorStack or its customers.
Sensitive information
Information classified as confidential or restricted, including customer data, credentials, personal information, financial information, security data, and proprietary business information.
Security incident
An event that actually or potentially compromises the confidentiality, integrity, or availability of information or systems, or violates a security policy.

Questions about this policy, security concerns, and vulnerability reports may be sent to it@vectorstack.us.