← Governance framework
Platform Operations

Information Security Policy

Baseline security controls covering identity, network, application, data and supply chain.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
Head of Security
Approver
Board of Trustees
Anchored by content hashissued 2026-07-29
Payload hash
c3a2edd31362958c7b3462da5662ed87193ae05d543cb80c3f40be6376f14954
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:c3a2edd31362958c

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • All ImpactMiles systems
  • All staff and contractors

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • RLS on every public schema table
  • Server-only secrets (TAS, Veraf, service role) never shipped to client
  • Signed webhooks for all inbound public endpoints

1. Identity and Access

  • SSO with MFA required for all staff.
  • Least privilege by role.
  • Quarterly access reviews.

2. Application Security

  • Server functions authorised via requireSupabaseAuth and role checks.
  • Dependency scanning on every build.
  • Annual third-party penetration test.

3. Data Security

  • Encryption in transit (TLS 1.2+) and at rest.
  • Private storage bucket for KYB/licence evidence.
  • Row Level Security enforced on all user-facing tables.
Questions or concerns about this policy? Contact the DPO.

Related policies