Policies Internal operating policies

Vendor Security Policy

Security requirements Map.ca holds vendors to before, during, and after engagement.

Version
0.1.0
Effective
May 20, 2026
Last reviewed
May 20, 2026
Review cycle
every 6 months
Master Policy Index entry
§4 #66

Policy text

Map.ca’s security posture is only as strong as its weakest vendor. The Vendor Security Policy defines the pre-engagement security review, the contractual security requirements, the ongoing monitoring expectations, the incident notification SLAs Map.ca requires from vendors, and the off-boarding process that ensures data is returned or destroyed at end of engagement.

It applies to the Map.ca procurement, security, legal, and engineering functions, and to every vendor with access to Map.ca production or personal data.

Principles this policy enforces

  • Collect less, protect more
  • Public data and personal data are not the same thing
  • Community benefit must survive scale

What it requires

  • Perform a documented security review before engagement.
  • Require contractual incident notification SLAs.

What it forbids

  • Do not engage a vendor handling personal data without a security review.
  • Do not allow indefinite vendor data retention after off-boarding.

How it applies

References