Security Addendum — postal.ID
This addendum describes baseline security commitments for the Services. Detailed TOMs are in the DPA Annex 2.
1. Access controls
- RBAC with least privilege.
- MFA for admin roles (recommended/required).
- Audit logs for key actions (case creation, evidence download, policy changes).
2. Encryption
- Encryption in transit (TLS).
- Encryption at rest for sensitive data.
- OTPs stored hashed (not plaintext).
3. Logging and monitoring
- Centralized logs, alerting, and anomaly detection for production.
- Retention aligned to security needs and privacy requirements.
4. Vulnerability management
- Regular patching and dependency management.
- Penetration testing cadence: [annual] (or as committed).
5. Incident response
- Documented incident response plan.
- Customer notifications per DPA.
6. Business continuity
- Backups and disaster recovery procedures.
- Recovery targets: [RPO/RTO placeholders].
7. Subprocessor security
- Due diligence and contractual controls for subprocessors.