Policies Internal operating policies
Vendor Security Policy
Security requirements Map.ca holds vendors to before, during, and after engagement.
- Version
- 0.1.0
- Effective
- May 20, 2026
- Last reviewed
- May 20, 2026
- Review cycle
- every 6 months
- Master Policy Index entry
- §4 #66
Policy text
Map.ca’s security posture is only as strong as its weakest vendor. The Vendor Security Policy defines the pre-engagement security review, the contractual security requirements, the ongoing monitoring expectations, the incident notification SLAs Map.ca requires from vendors, and the off-boarding process that ensures data is returned or destroyed at end of engagement.
It applies to the Map.ca procurement, security, legal, and engineering functions, and to every vendor with access to Map.ca production or personal data.
Principles this policy enforces
- Collect less, protect more
- Public data and personal data are not the same thing
- Community benefit must survive scale
What it requires
- Perform a documented security review before engagement.
- Require contractual incident notification SLAs.
What it forbids
- Do not engage a vendor handling personal data without a security review.
- Do not allow indefinite vendor data retention after off-boarding.
How it applies
- Procurement
- Security
- Legal
- Engineering
- Vendors with production or personal data access
References
- PIPEDA — Accountability principle (third-party processors)
Related policies
Security Policy
How Map.ca protects accounts, infrastructure, secrets, and operational data day to day.
AI Vendor Policy
Standards that AI vendors must meet to handle Map.ca traffic — data handling, training restrictions, audit requirements.
Access Control Policy
How internal access to production systems, user data, and admin functions is granted, reviewed, and revoked.