isotope13 LLC: Corporate Policies

Revised · policies/CORPORATE.md · 40d615a192f0

Acceptable Use

Don't be a jerk. Don't break the law.

Access Control

You get the access you need and nothing more, reviewed regularly. Authentication requires a physical security key—no exceptions.

Artificial Intelligence

We use AI. We do not let models train on your data.

Business Continuity & Backups

Our production API endpoints run independently in 4 US regions. We back up all critical data.

Change Management

Every production change is documented, and every code and config change is reviewed before going live. Dev stays separate from production.

Compliance

We are working towards SOC 2 and GDPR compliance with annual third-party audits. Findings are tracked and fixed on schedule.

Data Lifecycle

We store no customer data. What we do hold is encrypted at rest and in transit.

Incident Response

Something breaks, we fix it fast. Critical incidents, security or otherwise, reach affected customers within 24 hours.

Physical Assets

Every device is tracked and fully encrypted. Retired devices are destroyed using NIST SP 800-88 techniques.

Risk Management

We assess risk yearly to spot threats and plan long-term mitigations.

Security Operations

We avoid running our own operating system stack. Where we must, environments stay patched, firewalled, and monitored, with critical patches applied within 8 hours.

Vendor

We avoid third-party vendors where possible. The ones we use face a yearly security review. See Approved Subprocessors.