Trust & Security
Physical Security Policy
Version 1.0 · Effective: July 16, 2026 · Reviewed annually · Public edition — certain internal operational details have been generalized for publication.
This policy protects Penusila Digital Solutions' people, workspaces, equipment, and physical records from unauthorized access, theft, and damage. In brief: work areas are access-controlled with individually issued badges and keys; visitors are escorted at all times; desks are kept clear of confidential material and screens locked when unattended; all devices use full-disk encryption and are never left exposed; confidential documents are cross-cut shredded — never binned; and every loss, theft, or suspicious event is reported within 24 hours. Because the Company hosts all production systems out-of-house with hardened cloud providers — Amazon Web Services (AWS), Cloudflare, and Base44 (our managed application platform, whose backend runs on AWS-based infrastructure) — whose data centers are independently audited under SOC 2 Type II and ISO 27001, the physical security of production infrastructure is inherited from those providers, while the Company secures everything it directly controls to the highest practical standard.
1. Purpose
This policy defines the measures Penusila Digital Solutions ("the Company") uses to protect people, offices, equipment, and physical records from unauthorized access, theft, damage, and other physical threats. Physical security is a foundation of our overall security program: encryption, access controls, and monitoring only protect data if the devices and spaces that hold that data are also protected.
2. Scope
This policy applies to:
- All employees, contractors, interns, and temporary staff ("personnel").
- All Company facilities, including offices, meeting spaces, and any co-working or shared spaces used for Company business.
- All Company equipment: laptops, phones, tablets, external drives, badges/keys, and networking hardware.
- All physical records containing Company, customer, or partner information, in any location (office, home office, or in transit).
Note on production infrastructure. Penusila Digital Solutions does not operate its own server rooms or data centers. Our products are hosted with vetted cloud providers — Amazon Web Services (AWS) for compute and storage, Cloudflare for the edge network, DNS, TLS, and DDoS/WAF protection, and Base44, our managed application platform (whose backend runs on AWS-based infrastructure). Physical security of production servers is provided by those providers' hardened data centers (independently audited under programs such as SOC 2 and ISO 27001, with 24/7 on-site security, biometric access control, and camera surveillance). Section 10 covers how we manage that relationship.
3. Facility Access Control
- Badges and keys. Access to Company work areas is granted only to authorized personnel. Badges, keys, access codes, and fobs are issued individually, must not be shared or loaned, and must be returned on the last day of employment or engagement.
- Least privilege. Access is granted to the areas a person needs for their role and no more. Access rights are reviewed at least annually and revoked immediately upon role change or departure.
- Lost or stolen credentials. Lost or stolen badges, keys, or codes must be reported to management the same day so they can be deactivated or rekeyed.
- Doors and locks. Exterior doors and doors to restricted areas must remain locked outside business hours. The last person leaving is responsible for confirming doors and windows are secured.
- Tailgating. Personnel must not allow unknown individuals to follow them through secured doors. Politely direct anyone without a badge to reception or a manager.
4. Visitors
- Visitors must be pre-arranged or checked in on arrival, and must be escorted by a member of staff at all times while in non-public areas.
- Visitors must never be left unattended near workstations, whiteboards, printers, or documents containing confidential information.
- Visitor access ends when the visit ends; any temporary badge or code is collected or expired on departure.
- Service providers (cleaning, maintenance, delivery) are given access only to the areas required and, where possible, work during staffed hours.
5. Security Cameras and Monitoring
- Where the Company controls a facility, entrances and shared areas may be monitored by security cameras and/or alarm systems. Cameras are used for security purposes only, positioned to respect privacy (never in restrooms or private areas), and recordings are retained only as long as needed and access-restricted.
- In shared or co-working spaces, the Company relies on the facility operator's monitoring and access-control systems; personnel should treat such spaces as semi-public and apply the clean-desk and device-locking rules below with extra care.
6. Clean-Desk and Clear-Screen Practices
- Desks must be cleared of confidential papers, sticky notes with credentials, badges, and removable media when unattended and at the end of each day. Confidential material is stored in locked drawers or cabinets.
- Screens must be locked whenever a device is left unattended, and automatic screen lock must be enabled with a short timeout.
- Whiteboards containing sensitive information must be erased after use.
- Printouts containing confidential information must be collected from printers immediately.
- Passwords must never be written down or posted anywhere at a workspace.
7. Equipment Protection
- Company laptops and devices must use full-disk encryption, strong login credentials, and automatic screen lock. This is mandatory and verified at issuance.
- Devices must not be left visible in unattended vehicles, unattended in public places, or checked into luggage during travel.
- Equipment is inventoried at issuance. Personnel must report loss, theft, or damage the same day it is discovered (see Section 9).
- Devices leaving service are wiped using a secure erase process before disposal, resale, or recycling; drives that cannot be wiped are physically destroyed.
8. Physical Records and Secure Disposal
- The Company minimizes paper records; digital-first handling is the default. Where physical records containing confidential information must exist, they are stored in locked cabinets with access limited to those who need them.
- Confidential documents that are no longer needed must be destroyed by cross-cut shredding (or an equivalent certified destruction service) — never placed in regular trash or recycling.
- Removable media (USB drives, external disks, backup media) containing Company data must be encrypted, stored locked when not in use, and physically destroyed or securely wiped at end of life.
- Records subject to retention requirements are destroyed only after their retention period expires, in line with the Company's Data Management Policy.
9. Incident Reporting
Personnel must report the following to management/security immediately, and in all cases within 24 hours:
- Lost or stolen devices, badges, keys, or media.
- Break-ins, attempted break-ins, or signs of tampering.
- Unescorted or suspicious individuals in work areas.
- Confidential documents found unsecured or improperly disposed of.
Prompt reporting is treated as good citizenship, not grounds for blame. Delayed reporting that increases harm may result in disciplinary action.
10. Cloud and Out-of-House Hosting
Because our production systems are hosted out-of-house with providers — Amazon Web Services (AWS), Cloudflare, and Base44 (our managed application platform, whose backend runs on AWS-based infrastructure) — the Company:
- Selects providers whose data centers hold recognized certifications (SOC 2 Type II, ISO 27001) and provide physical safeguards we could not economically replicate: 24/7 security staff, biometric and multi-factor entry controls, CCTV, redundant power and environmental controls.
- Reviews provider security documentation and shared-responsibility models, and ensures that what remains our responsibility — account security, encryption of data in transit and at rest, access control, and key management — is implemented to the highest standard we can achieve.
- Restricts administrative access to hosting consoles to named individuals using multi-factor authentication.
11. Enforcement
Violations of this policy may result in disciplinary action up to and including termination of employment or contract, and where applicable, legal action. Exceptions to this policy require written approval from the policy owner.
Related Policies
See also our Data Management Policy, Remote Work Policy, and Security & Data Protection overview. Questions can be sent to hello@penusiladigitalsolutions.org.