Cybersecurity Policy

Protecting our systems, our clients' data and our intellectual property is everyone's job — founder, contractor and intern alike.

Authentication and access

  • Strong, unique passwords everywhere, held in a password manager — never reused across services.
  • Two-factor authentication is mandatory on every company account: email, GitHub, trackers, cloud consoles, financial systems.
  • Least privilege. Access is granted by role and necessity, and removed when the need ends.
  • Passwords are never shared. Not with colleagues, not with founders, not with support. No legitimate Cuesoft process asks for your password — treat any such request as an incident and report it.

Credentials and secrets

  • Secrets (API keys, tokens, service credentials) live in the approved secret manager — never in code, never in repositories, never in chat.
  • Nothing sensitive travels through WhatsApp. Client groups are for coordination; credentials and access requests go through the engagement's formal email channel.
  • Rotations and access changes on production systems go through the engagement lead — unauthorised changes are a violation.

Data storage

  • Confidential files and client data live only in approved company systems. Personal cloud accounts and personal USB storage are prohibited for company data.
  • Sensitive data is encrypted in storage and in transit.

Devices and networks

  • Keep your work device's OS patched, disk encrypted, screen locked, and protected with up-to-date security tooling (see BYOD).
  • Use secure networks; on public Wi-Fi, use a VPN.
  • A lost or stolen device that touched company or client data is reported immediately so access can be revoked.

Threats and incidents

  • Be suspicious of unexpected links, attachments and urgent requests — phishing is the front door of most breaches.
  • Report suspected phishing, malware, breaches or unusual account activity immediately to hello@cuesoft.io. Fast reports contain damage; delayed ones compound it. Personal-data incidents also follow the data-protection policy clock.

Last updated 2026-08-16.