Physical & Environmental Security Policy
1. Purpose
To address physical and environmental security for Backpack Works, a distributed team that relies on cloud infrastructure.
2. Cloud data centers
We do not operate our own data centers. Physical and environmental security for hosting is provided by our cloud platforms (Vercel, WP Engine, Supabase, Cloudflare), which maintain their own certifications (SOC 2, ISO 27001).
3. Workspaces & devices
- Company devices use full-disk encryption and automatic screen lock.
- Personnel keep devices physically secure and do not leave them unattended in public.
- Devices must not be left visible in unattended vehicles.
- Lost or stolen devices must be reported immediately so access can be revoked.
4. Visitors
When working from shared or client spaces, personnel protect screens and confidential materials from unauthorized viewing.
5. Review
This policy is reviewed at least annually.