Version 1.0 · Draft · Owner: HR
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: [HR / Security Lead]
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Define security requirements for Touch2Sign personnel working remotely or from non-office locations. Protects customer data and production systems when accessed outside Touch2Sign premises.
Applies to all employees and contractors who:
Touch2Sign production systems are cloud-hosted (AWS eu-west-1). Remote access is permitted via:
Direct RDS or S3 access from remote locations requires MFA, least-privilege IAM, and approved tooling — never public endpoints.
| Requirement | Company device | BYOD (approved) | Full-disk encryption | Required | Required |
|---|---|---|
| OS auto-updates | Required | Required |
| Screen lock (≤ 5 min) | Required | Required |
| Antivirus / endpoint protection | Required | Required |
| Firewall enabled | Required | Required |
| Jailbroken / rooted devices | Prohibited | Prohibited |
| Shared family computer for production access | Discouraged | Prohibited without CEO exception |
BYOD must be registered with IT/Security and removed at engagement end.
VPN is not required for standard application access when MFA and TLS protect the session. VPN or AWS Session Manager may be mandated for specific break-glass or database administration tasks.
Remote workers must:
Video calls: use background blur; do not share screen with customer documents visible unless necessary for support.
| Practice | Requirement | Home Wi-Fi | WPA2/WPA3; change default router password |
|---|---|
| Public Wi-Fi | Acceptable for MFA-protected HTTPS access; avoid public Wi-Fi for AWS console without additional caution |
| Public hotspots | Do not access Restricted data on untrusted networks without encrypted tunnel if mandated by Security Lead |
| Personal hotspots | Preferred over café Wi-Fi for sensitive tasks |
Report from any location:
Follow Incident Response Plan — preserve evidence; do not self-remediate production without guidance.
Reviewed annually and when remote work practices or tooling changes.
Approval
| Name | Role | Signature | Date | Robert | CEO / Security Lead | Electronic | 11 July 2026 |
|---|
Questions: security@touch2sign.com · privacy@touch2sign.com