Last updated July 20, 2026
Security is part of how we build and ship.
Security is integrated into design, development, testing, and release. We follow our Secure Development Policy covering code review, dependency management, and environment separation.
Changes to production code undergo peer review with security considerations for authentication, authorization, and data handling.
Third-party dependencies are tracked and updated to address known vulnerabilities.
Development, staging, and production environments are logically separated. Production data is not used in non-production environments without controls.
Read the full Secure Development Policy in our Trust Center policy library for detailed requirements on CI/CD security, static analysis, and secure releases.
Requirements for granting, reviewing, and revoking access to DotlyMaps systems.
Version 1.0
Backup frequency, encryption, and recovery testing requirements.
Version 1.0
Formal incident response lifecycle for security events.
Version 1.0
Overarching information security program for DotlyMaps.
Version 1.0
Password and credential requirements for DotlyMaps systems.
Version 1.0
Security requirements for the software development lifecycle.
Version 1.0
Third-party vendor and subprocessor security requirements.
Version 1.0
Responsible disclosure and vulnerability reporting process.
Version 1.0