← Governance framework
Platform Operations
Information Security Policy
Baseline security controls covering identity, network, application, data and supply chain.
- Version
- v1.0
- Effective
- 2026-07-19
- Last reviewed
- 2026-07-19
- Next review
- 2027-07-19
- Owner
- Head of Security
- Approver
- Board of Trustees
Anchored by content hashissued 2026-07-29
Payload hash
c3a2edd31362958c7b3462da5662ed87193ae05d543cb80c3f40be6376f14954SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhEParty that issued this receipt
ImpactMiles handle
audit:governance:c3a2edd31362958cThis receipt is anchored by content hash. A resolvable credential SAID is not available for this record.
Applies to
- All ImpactMiles systems
- All staff and contractors
Jurisdictions
- Hong Kong (PDPO, IRD s.88)
- United Kingdom (UK GDPR, DPA 2018)
- European Union (GDPR)
- Singapore (PDPA)
- Australia (Privacy Act 1988)
- Japan (APPI)
- Wider APAC per country taxonomy
How this is applied in-product
- RLS on every public schema table
- Server-only secrets (TAS, Veraf, service role) never shipped to client
- Signed webhooks for all inbound public endpoints
1. Identity and Access
- SSO with MFA required for all staff.
- Least privilege by role.
- Quarterly access reviews.
2. Application Security
- Server functions authorised via requireSupabaseAuth and role checks.
- Dependency scanning on every build.
- Annual third-party penetration test.
3. Data Security
- Encryption in transit (TLS 1.2+) and at rest.
- Private storage bucket for KYB/licence evidence.
- Row Level Security enforced on all user-facing tables.
Questions or concerns about this policy? Contact the DPO.