Skip to content

Human Resources Security Policy

Field Value
Owner Puneet Gupta (Co-Founder)
Classification Internal (shareable under NDA)
Version 1.0
Effective date 2026-06-11
Next review 2027-06-11

1. Purpose

Define security requirements for personnel across the engagement lifecycle — before, during, and after engagement.

2. Roles & responsibilities

Security roles and responsibilities for personnel handling scoped systems and data are defined and documented, consistent with the Information Security Policy.

3. Before engagement

  • Background verification — ID, criminal, and employment checks are performed for personnel with access to scoped systems and data. (Being introduced as a standard pre-engagement step; retroactive checks for current personnel are in progress.)
  • Agreements — all personnel sign written agreements including confidentiality / non- disclosure obligations, acceptable-use, and security responsibilities before access is granted.

4. During engagement

  • Personnel complete security awareness training (see Security Awareness & Training Policy).
  • Access is granted on least-privilege and reviewed periodically.

5. Disciplinary process

Security violations, breaches, or misuse of information processing facilities are subject to a disciplinary process, which may include suspension or revocation of access and termination, as set out in personnel agreements and this policy.

6. Offboarding

On termination of engagement, access is revoked promptly, and any company/customer data on the person's devices is removed (see BYOD & Endpoint Security Policy).

Revision history

Version Date Author Change Approved by
1.0 2026-06-11 Puneet Gupta Initial draft Puneet Gupta (Co-Founder)