1. Acceptable use
People working for SemantiqWall must:
- use company systems and customer data only for their job, and access customer data only when needed to operate, support or secure the service;
- never copy customer data to personal accounts, personal cloud storage, AI tools or removable media;
- never share credentials, disable MFA or security controls, or install unapproved remote-access software;
- keep secrets out of chat, e-mail, tickets and code;
- report lost devices, suspicious messages and possible incidents immediately (policy 05);
- when using AI coding or writing assistants, never paste secrets or production customer data into them; treat their output as untrusted and review it before use.
Unattended screens are locked; customer data is not left visible or printed. Work in public places uses a privacy screen or position that prevents shoulder surfing, and only trusted networks or a VPN for administration.
2. Approved services
Work is done only with: the private GitHub repository, the Hostinger panel and SSH to the production server, Resend, the GoDaddy Titan mailbox, the domain registrar, the approved AI provider (policy 09), a password manager and standard office tools. Adding a service that will hold company or customer data follows policy 09.
3. Endpoint inventory
The security register keeps the list of devices that can reach production or customer data: today the Founder's computer and mobile phone. Each entry records owner, model, operating system and the date the settings below were last checked.
4. Required endpoint settings
| Requirement | Status |
|---|---|
| Full-disk encryption (BitLocker, FileVault or equivalent) | To be verified |
| Automatic screen lock after 5 minutes or less, with password, PIN or biometrics | To be verified |
| Operating system and browser on automatic updates; supported OS version only | To be verified |
| Built-in anti-malware on (e.g. Microsoft Defender) | To be verified |
| OS firewall on | To be verified |
| Password manager for all company accounts | To be verified |
| SSH private keys protected by a passphrase or hardware key | To be verified |
| Remote locate and remote wipe enabled (computer and phone) | To be verified |
| No local copies of production database dumps or customer data, except temporarily during an incident, then deleted | Required |
Commitment: verify each item, fix what is missing, and record screenshots or command output as evidence in the register (owner: Founder, target 2026-10-15). After that, re-check every quarter and whenever a device is replaced.
Operating-system changes on endpoints happen through the vendor's automatic updates; a new device is set up to this checklist before it gets any company access. Data loss prevention (DLP) software is not used; the risk is managed by keeping customer data on the server and out of endpoints.
5. Lost or stolen devices
Report immediately; remotely lock and wipe; revoke the device's SSH keys and sessions; change passwords stored on it if the password manager was unlocked; record as an incident (policy 05).
6. Device disposal
Before a device is sold, recycled or returned, it is wiped with the operating system's secure reset (with disk encryption on, this destroys the key). Recorded in the register.
7. Personnel (mandatory from the first hire or contractor)
Today SemantiqWall has no employees or contractors with access to systems or data. Before the first person gets access:
- Screening: identity and reference checks, and a background check where lawful in the person's country, proportionate to the access.
- Agreements: a signed confidentiality agreement (NDA) and acceptance of this policy pack, as part of the contract.
- Onboarding: security and privacy training in the first week (this pack, phishing, incident reporting, LGPD basics); access granted per policy 01, at the lowest role.
- Ongoing: annual refresher training and re-acknowledgement of the policies; role-based training for anyone with production access.
- Roles: each person's security responsibilities are written in their role description.
- Changes and exit: access adjusted on role change; removed no later than the last working day; company devices and data returned; confidentiality duties continue after exit.
- Disciplinary process: breaches of these policies are handled under the employment or service contract, proportionate to the harm.
- Company-owned devices for staff are the default; personal devices need an exception (policy 00) and must meet section 4.
8. Third-party access
No supplier or third party has access to company endpoints. If that changes, the access is time-limited, supervised and recorded in the register.