Policies Internal operating policies

Security Policy

How Map.ca protects accounts, infrastructure, secrets, and operational data day to day.

Version
0.1.0
Effective
May 20, 2026
Last reviewed
May 20, 2026
Review cycle
every 6 months
Master Policy Index entry
§4 #61

Policy text

Security is a precondition for trust, not a feature. The Security Policy defines Map.ca’s operating standard for account security (MFA on admin, password discipline for users), data security (encryption at rest and in transit), infrastructure security (production access controls, secrets management, dependency hygiene), and operational security (monitoring, audit logging, vendor security review). PIPEDA’s safeguards principle is the regulatory floor; Map.ca’s practical bar is higher.

It applies to Map.ca engineering, security, operations, and to any vendor with production access. Production credentials in source control, shared admin accounts, and unmonitored access are non-starters.

Principles this policy enforces

  • Collect less, protect more
  • Public data and personal data are not the same thing
  • Community benefit must survive scale

What it requires

  • Encrypt personal and sensitive data at rest and in transit.
  • Enforce MFA on all admin accounts and on accounts with production access.
  • Rotate credentials on a documented schedule.
  • Monitor and audit-log production access continuously.

What it forbids

  • Do not commit production credentials, secrets, or keys to source control.
  • Do not share admin accounts between people.
  • Do not provision production access without monitoring and audit logging.
  • Do not bypass security review for vendor integrations handling production data.

How it applies

References