Acceptable Use Policy
Scope
The policy applies to every person performing work for Hybrowlabs, regardless of employment status or location, and to every device used for that work. It applies equally to Hybrowlabs-owned systems and to customer systems accessed under an engagement.
Approved systems and accounts
Customer work is performed using Hybrowlabs-issued accounts on approved systems. Personal accounts, personal email addresses and personal cloud storage are not used for customer work, customer communication or storage of customer material.
New tools, browser extensions, integrations and third-party services are approved by operations before use where they will touch customer data. A tool that requires access to a customer instance, repository or mailbox is treated as a subprocessor and is assessed under the Vendor / Subprocessor Management Policy before it is connected.
Acceptable use
Approved systems and customer data may be used only for authorised business purposes: implementation, configuration, development, migration, testing, support, and the internal operations required to deliver and invoice that work.
Access to a customer environment is exercised only where the task in hand requires it and only to the extent it requires. Reasonable incidental personal use of company systems is permitted where it does not interfere with work, consume significant resources, or involve customer data.
Prohibited use
The following are not permitted under any circumstances:
- Sharing, reusing or storing credentials outside the approved password manager
- Using another person's account, or allowing another person to use yours
- Bypassing, disabling or weakening access controls, logging, endpoint protection or backup processes
- Accessing customer records out of curiosity, for personal interest, or on behalf of anyone other than the customer
- Copying customer data to personal devices, personal accounts, unmanaged storage or unapproved messaging tools
- Removing or exporting customer data at the end of an engagement other than as the contract requires
- Installing unlicensed, pirated or untrusted software on a device used for customer work
- Using customer data or customer credentials for demonstrations, testing, training material, portfolio content or marketing
- Any illegal activity, harassment, or use of company systems to attack, scan or probe a system without written authorisation
Customer data handling
Customer data is collected and held to the minimum required for delivery. Production data is not copied into development or demonstration environments unless the customer has authorised it in writing, and it is masked or anonymised where the work allows.
Exports, backups, screenshots, log files, error traces and support attachments frequently contain customer data and are treated accordingly. They are shared only through approved channels, restricted to the people who need them, and deleted once the task that required them is closed.
Credentials and access
Credential rules apply without exception:
- Credentials are issued to named individuals
- Multi-factor authentication is enabled on every system that supports it
- Passwords are stored in the approved password manager
- Passwords are never placed in code, configuration files, spreadsheets, chat messages or documentation
API keys, tokens and SSH keys are:
- Issued for a specific purpose
- Not shared between people or projects
- Rotated when someone with knowledge of them leaves the account
Administrative access to a customer production environment is a separate approval held by the smallest possible number of people. It is used for the specific change it was granted for, and elevated actions are performed under a change record rather than ad hoc.
Devices and remote working
Devices used for customer work have:
- Full disk encryption
- An automatic screen lock
- Current operating system patches
- Endpoint protection enabled
Devices are not left unattended and unlocked in shared or public spaces. Customer work is performed over a trusted network. Public wireless networks are avoided for administrative access. Any customer-side requirement, such as VPN, jump host or IP allowlisting, is followed in addition to these controls.
Lost or stolen devices are reported to Operations immediately so that sessions can be terminated and credentials rotated.
Communication channels
Customer communication takes place through the channels agreed with that customer. Where a customer specifies a channel or prohibits one, that instruction governs.
Customer names, screenshots, configuration details, commercial terms and project specifics are not posted on social media, community forums, public issue trackers or public code repositories. Case studies, testimonials and public references are published only with the customer's written consent.
Use of AI and external services
Customer data, source code, credentials and confidential documents are not pasted into public AI tools, code assistants, translation services, file converters, or any external service that has not been approved. Approved tools are recorded, and any customer restriction on AI usage is applied to that account.
Customer-specific requirements
Where a customer contract imposes stricter conditions than this policy, including restrictions on tooling, location of work, device ownership or data handling, those conditions take precedence for that account. Hybrowlabs will provide evidence of compliance on request.
Monitoring and enforcement
Hybrowlabs systems and access to customer environments may be logged and reviewed for security, compliance and operational purposes. Monitoring is proportionate, is limited to what is required for those purposes, and is conducted in line with applicable law.
Suspected breaches are investigated by Operations, with access suspended during the investigation where there is a credible risk to customer data. Outcomes range from retraining and formal warning to removal of privileged access, termination of employment or contract, and referral to law enforcement. Customers are notified where their data is affected, within the timelines set out in the applicable agreement.
Exceptions
Exceptions are requested in writing, approved by the Director, recorded with a business justification and an expiry date, and reviewed before renewal.
Evidence maintained
Hybrowlabs maintains the following records and can produce them for customer due diligence or audit, subject to redaction of personal data:
- Signed policy acknowledgements
- Security awareness training completion records
- Approved tool and subprocessor register
- Access approval and revocation records
- Exception requests, approvals and expiry dates
- Incident and violation records
Related documents
- HR Security Policy
- Background Verification Process
- NDA / Confidentiality Agreement Structure
- Security Awareness Training Evidence Structure
- Vendor / Subprocessor Management Policy
- Subprocessor Register