Template document, review with qualified legal counsel before reliance.

Information Security Policy

Version 1.0Effective July 20, 2026Last reviewed July 20, 2026

Overarching information security program for DotlyMaps.

Purpose

This policy establishes the information security program for DotlyMaps and defines minimum requirements to protect customer data, intellectual property, and operational systems.

Scope

This policy applies to all DotlyMaps personnel, contractors, systems, and facilities involved in developing, operating, or supporting the DotlyMaps platform.

Roles and responsibilities

  • Executive leadership approves the security program and allocates resources.

  • Security team maintains policies, monitors controls, and coordinates incident response.

  • Engineering implements secure development and infrastructure practices.

  • All personnel follow security policies and report suspected incidents.

Risk management

DotlyMaps identifies, assesses, and treats information security risks based on likelihood and impact. Risk treatment decisions are documented and reviewed periodically.

Access control

Access to systems and data follows least privilege and role-based access control. Access is provisioned, reviewed, and revoked per the Access Control Policy.

Asset management

Information assets are inventoried, classified by sensitivity, and protected according to their classification.

Encryption

Sensitive data is encrypted in transit using TLS and at rest using industry-standard encryption on managed infrastructure.

Secure development

Software is developed per the Secure Development Policy including code review, dependency management, and secure release practices.

Incident response

Security incidents are handled per the Incident Response Policy with defined roles, communication paths, and post-incident review.

Vendor security

Third-party vendors are assessed per the Vendor Security Policy before processing customer data.

Business continuity

Availability and recovery objectives are defined in the Business Continuity Policy with tested backup and restore procedures.

Continuous improvement

This policy and related standards are reviewed at least annually and updated based on threat landscape changes, audit findings, and customer requirements.