SecurityPolicies

Policies

Our compliance program is based on the following internal policies:

  • Acceptable Use Policy
  • Asset Management Policy
  • Backup Policy
  • Business Continuity Plan
  • Change Management Policy
  • Code of Conduct
  • Data Classification Policy
  • Data Protection Policy
  • Data Retention Policy
  • Disaster Recovery Plan
  • Encryption Policy
  • Incident Response Plan
  • Information Security Management System (ISMS) Plan
  • Information Security Policy
  • Password Policy
  • Physical Security Policy
  • Responsible Disclosure Policy
  • Risk Assessment Policy
  • Software Development Life Cycle Policy
  • System Access Control Policy
  • Vendor Management Policy
  • Vulnerability Management Policy

Polyaxon maintains an internal wiki of security policies, which is updated on an ongoing basis and reviewed annually for gaps.

Corporate Security

Malware Protection

At Polyaxon, we believe that good security practices start with our own team, so we go out of our way to protect against internal threats and local vulnerabilities. All company-provided workstations have full-disk encryption, screen lock, and other security features.

Risk Management

Polyaxon follows the risk management procedures outlined in NIST SP 800-30, which include nine steps for risk assessment and seven steps for risk mitigation.

All Polyaxon product changes must go through code review, CI, and build pipeline to reach production servers. Only designated employees on Polyaxon's operations team have secure shell (SSH) access to production servers.

We perform testing and risk management on all systems and applications on a regular and ongoing basis. New methods are developed, reviewed, and deployed to production via pull request and internal review. New risk management practices are documented and shared via staff presentations on lessons learned and best practices.

Background Checks

Polyaxon conducts background checks for all new hires.

Security Training

All new employees receive onboarding and systems training, including environment and permissions setup, formal software development training (if pertinent), security policies review, company policies review, and corporate values and ethics training.

All engineers review security policies as part of onboarding and are encouraged to review and contribute to policies via internal documentation. Any change to policy affecting the product is communicated as a pull request, such that all engineers can review and contribute before internal publication. Major updates are communicated via email to all Polyaxon employees.