Backpack Works logo
All policies
Version: 1.0Last updated: December 2025Owner: Security Lead

Physical & Environmental Security Policy

1. Purpose

To address physical and environmental security for Backpack Works, a distributed team that relies on cloud infrastructure.

2. Cloud data centers

We do not operate our own data centers. Physical and environmental security for hosting is provided by our cloud platforms (Vercel, WP Engine, Supabase, Cloudflare), which maintain their own certifications (SOC 2, ISO 27001).

3. Workspaces & devices

  • Company devices use full-disk encryption and automatic screen lock.
  • Personnel keep devices physically secure and do not leave them unattended in public.
  • Devices must not be left visible in unattended vehicles.
  • Lost or stolen devices must be reported immediately so access can be revoked.

4. Visitors

When working from shared or client spaces, personnel protect screens and confidential materials from unauthorized viewing.

5. Review

This policy is reviewed at least annually.