# Remote Working Policy

**Touch2Sign Ltd**  
**Version:** 1.0  
**Effective date:** 11 July 2026  
**Owner:** [HR / Security Lead]  
**Approved by:** Robert — CEO / Managing Director  
**Next review:** 11 July 2027

---

## 1. Purpose

Define security requirements for Touch2Sign personnel working remotely or from non-office locations. Protects customer data and production systems when accessed outside Touch2Sign premises.

## 2. Scope

Applies to all employees and contractors who:

- Work from home, co-working spaces, or while travelling  
- Access Touch2Sign email, Slack, GitHub, AWS, or customer data remotely  
- Use personal or company-issued devices for Touch2Sign work  

## 3. Approved remote access

Touch2Sign production systems are cloud-hosted (AWS eu-west-1). Remote access is permitted via:

- HTTPS to Touch2Sign application and admin interfaces  
- AWS Console / CLI with MFA  
- GitHub with MFA  
- VPN to AWS resources **not required** when MFA is enforced on all privileged access paths  

Direct RDS or S3 access from remote locations requires MFA, least-privilege IAM, and approved tooling — never public endpoints.

## 4. Device requirements

| Requirement | Company device | BYOD (approved) |
|-------------|----------------|-----------------|
| Full-disk encryption | Required | Required |
| OS auto-updates | Required | Required |
| Screen lock (≤ 5 min) | Required | Required |
| Antivirus / endpoint protection | Required | Required |
| Firewall enabled | Required | Required |
| Jailbroken / rooted devices | Prohibited | Prohibited |
| Shared family computer for production access | Discouraged | Prohibited without CEO exception |

BYOD must be registered with IT/Security and removed at engagement end.

## 5. Authentication

- **MFA mandatory** for AWS, GitHub, Cognito admin, and email — see Access Control Policy  
- No saving production passwords in unsecured browser profiles on shared devices  
- WebAuthn/passkeys preferred over SMS where supported  

VPN is **not required** for standard application access when MFA and TLS protect the session. VPN or AWS Session Manager may be mandated for specific break-glass or database administration tasks.

## 6. Physical security — clean desk

Remote workers must:

- Position screens away from public view where practicable  
- Lock screen when leaving device unattended  
- Not discuss Confidential or Restricted customer data in public spaces  
- Store printed materials securely; cross-cut shred when discarded  
- Not leave devices in unattended vehicles  

Video calls: use background blur; do not share screen with customer documents visible unless necessary for support.

## 7. Network security

| Practice | Requirement |
|----------|-------------|
| Home Wi-Fi | WPA2/WPA3; change default router password |
| Public Wi-Fi | Acceptable for MFA-protected HTTPS access; avoid public Wi-Fi for AWS console without additional caution |
| Public hotspots | Do not access Restricted data on untrusted networks without encrypted tunnel if mandated by Security Lead |
| Personal hotspots | Preferred over café Wi-Fi for sensitive tasks |

## 8. Data handling

- Customer documents and exports must not be stored on personal cloud (Dropbox, iCloud) without approval  
- Use Touch2Sign-approved systems only for Confidential data  
- Report lost or stolen devices within **4 hours** to security@touch2sign.com  
- Remote wipe enabled on company devices  

## 9. Incident reporting

Report from any location:

- Lost/stolen device  
- Suspected malware  
- Accidental customer data disclosure  
- Phishing targeting Touch2Sign credentials  

Follow **Incident Response Plan** — preserve evidence; do not self-remediate production without guidance.

## 10. Prohibited activities

- Allowing family members to use devices logged into Touch2Sign systems  
- Disabling encryption or MFA for convenience  
- Screen-recording customer signing sessions without consent  
- Working from sanctioned countries without Legal approval  

## 11. Related documents

- Acceptable Use Policy  
- Access Control Policy  
- Password & Authentication Standard  
- Data Classification Policy  
- Security Awareness Training  

## 12. Review

Reviewed **annually** and when remote work practices or tooling changes.

---

**Approval**

| Name | Role | Signature | Date |
|------|------|-----------|------|
| Robert | CEO / Security Lead | Electronic | 11 July 2026 |
