> ## Documentation Index
> Fetch the complete documentation index at: https://docs.buildbetter.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Information Security Policy Summary

> Summary of Build Better, Inc.'s core security and acceptable use practices

> **📄 Read and download the full Information Security Policy on our trust portal:**\
> [https://trust.buildbetter.ai/resources?s=82ed75cltv69qy292r9sgi\&name=information-security-policy-(aup)](https://trust.buildbetter.ai/resources?s=82ed75cltv69qy292r9sgi\&name=information-security-policy-\(aup\))

# Information Security Policy Summary

**Effective Date:** January 1, 2023\
**Policy Owner:** Spencer Shulem, CEO

## 🔐 Purpose & Scope

This policy outlines acceptable use and required protections for Build Better, Inc.’s systems, networks, and data. It applies to **all employees, contractors, and third parties** accessing Build Better, Inc. assets.

Security is a **shared responsibility**, and all personnel are required to act in accordance with this policy and report incidents promptly.

***

## 📦 Key Security Controls

### 🔒 Device & Mobile Security

* All end-user devices must be:
  * Locked with a password or biometric
  * Set to auto-lock after 5 minutes
  * Encrypted if storing or accessing confidential data
* Confidential data may **not** be stored on USB drives or personal devices.
* Lost or misused devices must be reported **immediately**.

### 🔐 Access Controls

* Passwords must follow the **Access Control Policy**.
* Users may not share credentials or leave devices unattended and unlocked.
* All VPN and remote access tools must be company-approved and use **MFA**.

### 🧹 Clear Desk & Clear Screen

* Users must **lock screens** when not in use.
* Confidential materials must not be left visible or unsecured in the workspace.

***

## 🌐 Acceptable Use & Unacceptable Activities

Build Better, Inc. systems are for **authorized business use only**. Prohibited activities include:

* Unauthorized software installs or access
* Network sniffing, denial of service, or unauthorized scanning
* Storing or transmitting copyrighted, offensive, or malicious material
* Sharing confidential data without permission
* Bypassing security mechanisms or using rogue software

***

## 🛡️ Incident Reporting

All suspected security incidents or policy violations must be reported **immediately** to:\
📧 **[security@buildbetter.app](mailto:security@buildbetter.app)**

**Whistleblower protections** are in place to encourage good-faith reporting of violations, fraud, or misconduct.

***

## 🌐 Remote Access & Public Network Use

* Only authorized, encrypted remote access (e.g., VPN with MFA) is permitted.
* Public Wi-Fi use requires VPN.
* Users must not save credentials or download data on public/shared machines.

***

## 📚 Linked Security Policies

This policy incorporates and references the following:

* ✅ Access Control Policy
* ✅ Cryptography Policy
* ✅ Data Management Policy
* ✅ Secure Development Policy
* ✅ Incident Response Plan
* ✅ Risk & Asset Management
* ✅ Business Continuity & Disaster Recovery
* ✅ Operations & Physical Security

Personnel are required to understand and follow all applicable linked policies.

***

## ✅ Compliance & Enforcement

* **Audits and monitoring** are conducted regularly.
* Violations may result in **disciplinary action**, including termination.
* **Exceptions** must be approved by the IT Manager.

***

> **📄 Read and download the full Information Security Policy on our trust portal:**\
> [https://trust.buildbetter.ai/resources?s=82ed75cltv69qy292r9sgi\&name=information-security-policy-(aup)](https://trust.buildbetter.ai/resources?s=82ed75cltv69qy292r9sgi\&name=information-security-policy-\(aup\))
