Seed-stage B2B SaaS startup
Sample for a fictional organisation · 1,927 words[Company] Information Security Policy
- Version: 1.0
- Owner: Founder / CTO
- Approved by: Founder / CTO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose
[Company] depends on the trust of its customers, who share personally identifiable information (PII) and other sensitive business data with the expectation that it will be handled carefully and kept secure. This policy sets out the principles and requirements that protect the confidentiality, integrity, and availability of [Company]'s systems, data, and the data entrusted to it by customers.
This policy is the top-level security policy for [Company]. It establishes the framework within which more detailed supporting policies and procedures (such as access control, incident response, and data management) operate. Where a topic is covered only briefly here, the relevant supporting policy contains the detailed requirements.
2. Scope
This policy applies to all [Company] employees, contractors, and any other individuals who access [Company] systems, applications, or data, regardless of location. It covers all information assets owned, managed, or processed by [Company], including cloud infrastructure, software applications, source code, communication tools, and any device used to access company systems or data.
Read the full example
[Company] Information Security Policy
- Version: 1.0
- Owner: Founder / CTO
- Approved by: Founder / CTO
- Effective date: [Effective date]
- Next review date: [Review date]
1. Purpose
[Company] depends on the trust of its customers, who share personally identifiable information (PII) and other sensitive business data with the expectation that it will be handled carefully and kept secure. This policy sets out the principles and requirements that protect the confidentiality, integrity, and availability of [Company]'s systems, data, and the data entrusted to it by customers.
This policy is the top-level security policy for [Company]. It establishes the framework within which more detailed supporting policies and procedures (such as access control, incident response, and data management) operate. Where a topic is covered only briefly here, the relevant supporting policy contains the detailed requirements.
2. Scope
This policy applies to all [Company] employees, contractors, and any other individuals who access [Company] systems, applications, or data, regardless of location. It covers all information assets owned, managed, or processed by [Company], including cloud infrastructure, software applications, source code, communication tools, and any device used to access company systems or data.
3. Policy
[Company] must protect its information assets and the data of its customers through a combination of reasonable technical controls, clear policies, and staff accountability appropriate to its size and risk profile. All personnel must understand and follow the requirements in this policy and its supporting policies, and must escalate any security concern promptly to the Founder / CTO.
4. Security Responsibilities
The Founder / CTO is responsible for information security at [Company] on a part-time basis, in addition to other duties. This includes setting security policy, managing access to core systems (AWS, Google Workspace, GitHub), reviewing security-relevant alerts, coordinating incident response, and acting as the primary point of contact for security questions from customers, auditors, or regulators. As [Company] works toward its first SOC 2 Type I report, the Founder / CTO is also responsible for maintaining evidence of the controls described in this policy and coordinating with any external auditor or advisor engaged to support that process.
Every employee and contractor is responsible for protecting the systems and data they use, following this policy, completing any security awareness activities requested of them, and reporting suspected security incidents or policy violations without delay. Given the small size of the team, [Company] does not operate a dedicated security committee; instead, security decisions are made directly by the Founder / CTO, with input from other team members as needed.
5. Device & Endpoint Security
All employees and contractors work remotely and must use company-approved or company-managed devices, or personal devices that meet the security requirements set by the Founder / CTO, to access [Company] systems or data. All devices used for work must have disk encryption enabled, a lock screen with a password or biometric lock, up-to-date operating system and application patches, and reputable anti-malware protection where applicable to the operating system.
Devices must not be shared with family members or other third parties while logged into company systems. Lost or stolen devices, or any suspected compromise of a device, must be reported to the Founder / CTO immediately so that access credentials can be revoked and affected accounts secured.
6. Application & Infrastructure Security
[Company]'s infrastructure runs in the cloud, primarily on AWS, with source code managed in GitHub and business collaboration conducted through Google Workspace. Access to these systems is restricted to personnel who need it for their role, must use unique credentials, and must be protected by multi-factor authentication (MFA) where the tool supports it. Changes to production infrastructure and application code must go through version control and, where practical, be reviewed by at least one other team member before deployment.
[Company] applies security patches and updates to its infrastructure and dependencies on a regular basis and monitors for known vulnerabilities in the software it builds and operates. Detailed configuration standards, access control rules, and change management procedures are set out in [Company]'s supporting access control and infrastructure policies.
7. Incident Response & Reporting
Any employee or contractor who suspects a security incident — including unauthorized access, data loss, malware, phishing, or loss of a device — must report it to the Founder / CTO as soon as possible, using [Security contact email] or the internal channel designated for this purpose. Prompt reporting is expected even where the individual is uncertain whether an event is a genuine incident.
The Founder / CTO is responsible for assessing reported incidents, containing and remediating them, and determining whether affected customers, regulators, or other parties must be notified under applicable law, including CCPA or other applicable US state privacy laws. Detailed steps for triage, containment, and notification are set out in [Company]'s incident response policy.
8. Whistleblower Policy
Any employee or contractor who becomes aware of illegal activity, unethical conduct, or a violation of this or any other [Company] policy may report it to the Founder / CTO, or, if the concern involves the Founder / CTO, to [Alternative contact]. Reports made in good faith are treated confidentially to the extent possible, and [Company] does not tolerate retaliation against anyone who raises a concern in good faith.
9. Fraud Reporting
Any suspected fraud, including misuse of company funds, falsification of records, or fraudulent activity by an employee, contractor, customer, or vendor, must be reported immediately to the Founder / CTO. Reports are investigated promptly and treated as confidentially as the circumstances allow.
10. Mobile Device Policy
Employees who use mobile phones or tablets to access company email, Google Workspace, or other business systems must protect those devices with a passcode or biometric lock, keep the operating system up to date, and enable remote wipe capability where supported. Company data must not be stored on mobile devices outside of approved applications, and any lost or stolen mobile device used for work must be reported to the Founder / CTO immediately.
11. Third-Party & Vendor Security
[Company] relies on third-party providers, including AWS, Google Workspace, and GitHub, to deliver its services. Before engaging a new vendor that will process customer data or PII, the Founder / CTO must assess the vendor's security and privacy practices and confirm that a written agreement is in place covering data protection obligations appropriate to the data involved.
[Company] maintains a list of vendors that process customer data and reviews this list periodically to confirm that each vendor remains appropriate and that access granted to each vendor is still required. Vendors are removed or access is revoked when a service is no longer in use.
12. Clear Screen / Clear Desk Policy
Because [Company] operates as a fully remote company with no shared office, employees must lock their screen whenever they step away from their device, whether working from home or in a public space, and must avoid displaying sensitive information on screen where others could view it, particularly in public or shared locations. Printed material containing customer data or PII should be avoided; where unavoidable, it must be stored securely and disposed of by shredding or secure deletion once no longer needed.
13. Remote Access Policy
As [Company] has no physical office, all access to company systems is remote by default. All remote access to AWS, GitHub, Google Workspace, and any other business system must use unique credentials and multi-factor authentication (MFA) where available, and must occur over a secured home or personal internet connection rather than unsecured public Wi-Fi wherever possible.
Employees and contractors must not use shared or public computers to access company systems and should use a personal or company-managed device configured in line with the Device & Endpoint Security section above. Where access to a sensitive system must occur from an unfamiliar network, the individual should use a virtual private network (VPN) or other secure connection method designated by the Founder / CTO.
14. Acceptable Use Policy
Company systems, accounts, and devices are provided for legitimate business purposes. Employees and contractors may make reasonable, incidental personal use of company systems (for example, checking personal email) provided this does not interfere with work, consume significant resources, or create security risk.
Where staff use AI tools as part of their work, they must not input customer PII, proprietary source code, or other confidential company or customer data into public or unapproved AI tools. Any AI tool used for business purposes must be approved by the Founder / CTO, and outputs from AI tools must be reviewed before being relied upon or shared externally.
15. Unacceptable Use
The following activities are prohibited on any [Company] system or device used for work:
- Sharing account credentials or access tokens with anyone, including other employees
- Disabling or circumventing security controls such as MFA, disk encryption, or endpoint protection
- Installing unauthorized or unlicensed software on devices used to access company systems
- Uploading customer data or source code to personal accounts or unapproved third-party services
- Using company systems to harass, defame, or discriminate against any person
Additional prohibited activities include:
- Attempting to access systems, data, or accounts beyond what is authorized for the individual's role
- Using company systems for illegal activity, including copyright infringement or fraud
- Connecting personal storage devices (such as USB drives) to company systems without approval
- Sending confidential company or customer data to personal email addresses
16. Email and Communication Activities
Employees must use company-provided Google Workspace accounts for business communication and follow these requirements:
- Do not open attachments or click links from unknown or unexpected senders
- Verify unusual or urgent payment or credential requests through a separate channel before acting
- Report suspected phishing emails to the Founder / CTO
- Do not forward customer data or PII to personal or unapproved third-party email accounts
- Use MFA on all company email and communication accounts
17. Compliance & Audits
[Company] is working toward its first SOC 2 Type I report and must maintain evidence that the controls described in this policy and its supporting policies are actually followed. The Founder / CTO is responsible for coordinating any internal review or external audit, including providing auditors, customers, or regulators with evidence of compliance where reasonably requested, consistent with applicable law such as CCPA.
18. Policy Review & Updates
The Founder / CTO reviews this policy at least annually, and more frequently if there is a significant change to [Company]'s systems, vendors, or legal obligations. Updates are communicated to all employees and contractors and take effect from the date they are issued.
19. Violations & Enforcement
Failure to comply with this policy may result in corrective action, up to and including termination of employment or contract, depending on the severity and nature of the violation. Where a violation involves illegal activity, [Company] may report the matter to law enforcement or other relevant authorities.
20. Policy Compliance
All employees and contractors must read, understand, and comply with this policy as a condition of accessing [Company] systems and data. The Founder / CTO may request written or electronic acknowledgment of this policy from each employee and contractor.
Disclaimer
This document is provided for informational purposes only and does not constitute legal advice. It is provided "as is", without warranty of any kind, express or implied, and no liability is accepted for any loss or damage arising from its use. It is used at your own discretion. Review it with a qualified adviser before adopting it.