Touch2Sign Policy Library
← All policies

Remote Working Policy

Version 1.0 · Draft · Owner: HR

Download .md →

Remote Working Policy

Touch2Sign Ltd

Version: 1.0

Effective date: 11 July 2026

Owner: [HR / Security Lead]

Approved by: Robert — CEO / Managing Director

Next review: 11 July 2027


1. Purpose

Define security requirements for Touch2Sign personnel working remotely or from non-office locations. Protects customer data and production systems when accessed outside Touch2Sign premises.

2. Scope

Applies to all employees and contractors who:

  • Work from home, co-working spaces, or while travelling
  • Access Touch2Sign email, Slack, GitHub, AWS, or customer data remotely
  • Use personal or company-issued devices for Touch2Sign work

3. Approved remote access

Touch2Sign production systems are cloud-hosted (AWS eu-west-1). Remote access is permitted via:

  • HTTPS to Touch2Sign application and admin interfaces
  • AWS Console / CLI with MFA
  • GitHub with MFA
  • VPN to AWS resources not required when MFA is enforced on all privileged access paths

Direct RDS or S3 access from remote locations requires MFA, least-privilege IAM, and approved tooling — never public endpoints.

4. Device requirements

Requirement Company device BYOD (approved)
Full-disk encryption Required Required
OS auto-updates Required Required
Screen lock (≤ 5 min) Required Required
Antivirus / endpoint protection Required Required
Firewall enabled Required Required
Jailbroken / rooted devices Prohibited Prohibited
Shared family computer for production access Discouraged Prohibited without CEO exception

BYOD must be registered with IT/Security and removed at engagement end.

5. Authentication

  • MFA mandatory for AWS, GitHub, Cognito admin, and email — see Access Control Policy
  • No saving production passwords in unsecured browser profiles on shared devices
  • WebAuthn/passkeys preferred over SMS where supported

VPN is not required for standard application access when MFA and TLS protect the session. VPN or AWS Session Manager may be mandated for specific break-glass or database administration tasks.

6. Physical security — clean desk

Remote workers must:

  • Position screens away from public view where practicable
  • Lock screen when leaving device unattended
  • Not discuss Confidential or Restricted customer data in public spaces
  • Store printed materials securely; cross-cut shred when discarded
  • Not leave devices in unattended vehicles

Video calls: use background blur; do not share screen with customer documents visible unless necessary for support.

7. Network security

Practice Requirement
Home Wi-Fi WPA2/WPA3; change default router password
Public Wi-Fi Acceptable for MFA-protected HTTPS access; avoid public Wi-Fi for AWS console without additional caution
Public hotspots Do not access Restricted data on untrusted networks without encrypted tunnel if mandated by Security Lead
Personal hotspots Preferred over café Wi-Fi for sensitive tasks

8. Data handling

  • Customer documents and exports must not be stored on personal cloud (Dropbox, iCloud) without approval
  • Use Touch2Sign-approved systems only for Confidential data
  • Report lost or stolen devices within 4 hours to security@touch2sign.com
  • Remote wipe enabled on company devices

9. Incident reporting

Report from any location:

  • Lost/stolen device
  • Suspected malware
  • Accidental customer data disclosure
  • Phishing targeting Touch2Sign credentials

Follow Incident Response Plan — preserve evidence; do not self-remediate production without guidance.

10. Prohibited activities

  • Allowing family members to use devices logged into Touch2Sign systems
  • Disabling encryption or MFA for convenience
  • Screen-recording customer signing sessions without consent
  • Working from sanctioned countries without Legal approval

11. Related documents

  • Acceptable Use Policy
  • Access Control Policy
  • Password & Authentication Standard
  • Data Classification Policy
  • Security Awareness Training

12. Review

Reviewed annually and when remote work practices or tooling changes.


Approval

Name Role Signature Date
Robert CEO / Security Lead Electronic 11 July 2026

Questions: security@touch2sign.com · privacy@touch2sign.com