Trust & Security
Remote Work Policy
Version 1.0 · Effective: July 16, 2026 · Reviewed annually · Public edition — certain internal operational details have been generalized for publication.
This policy defines how Penusila Digital Solutions personnel work securely from anywhere. In brief: remote work is available to roles that can be performed securely off-site, with manager approval; personnel keep agreed working hours and communicate over Company-approved channels only; Company-issued equipment ships with full-disk encryption, screen lock, and endpoint protection that must never be disabled; multi-factor authentication is mandatory on every account and the Company VPN is required on any untrusted network; home Wi-Fi must use WPA2/WPA3 with strong passphrases; Company data stays in Company systems — never personal email, personal cloud storage, or unencrypted drives; and incidents are reported within 24 hours. Underpinning all of this, our products are hosted out-of-house with hardened cloud providers — Amazon Web Services (AWS), Cloudflare, and Base44 (our managed application platform, whose backend runs on AWS-based infrastructure) — encrypted in transit (TLS 1.2+) and at rest (AES-256) — so remote work never requires sensitive data to live unprotected on a home device. We ensure the best security we practically can at every layer we control.
1. Purpose
This policy sets the expectations and security requirements for working outside the office. Penusila Digital Solutions operates as a modern, cloud-first company: our products are built and operated from wherever our people work, and hosted out-of-house with hardened cloud providers — Amazon Web Services (AWS), Cloudflare, and Base44 (our managed application platform, whose backend runs on AWS-based infrastructure). That model only works if every remote workspace upholds the same security bar as a controlled office — this policy defines that bar.
2. Scope
This policy applies to all employees, contractors, interns, and temporary staff ("personnel") performing Company work from any location outside a Company-controlled office: home offices, co-working spaces, travel, or any other remote setting. It covers work performed on Company-issued and (where approved) personal devices.
3. Eligibility and Approval
- Remote work is available to roles that can be performed effectively and securely off-site, as determined by management.
- Personnel handling especially sensitive data (production access, customer financial or personal data, admin consoles) may be subject to additional requirements before remote access is approved (e.g., verified device encryption, MFA enrollment, hardware security keys).
- The Company may revise or withdraw remote-work eligibility where security or performance requirements are not met.
4. Working Hours, Availability, and Communication
- Personnel agree on core working hours and availability with their manager and keep their calendar and status current.
- Company-approved channels (Company email, the Company's messaging and meeting tools) are used for business communication. Company business must not be conducted over personal email or unapproved messaging apps.
- Confidential conversations must not be held where they can be overheard (cafés, public transport), and screens showing sensitive data must not be readable by bystanders — use privacy screens in public where practical.
5. Company Equipment
- The Company issues laptops and equipment configured to Company standards: full-disk encryption, automatic screen lock, endpoint protection, and automatic security updates. Do not disable or alter these controls.
- Company equipment is for authorized users only — family members and others must not use Company devices.
- Personal devices may be used for Company work only with prior approval, and only if they meet the same baseline: OS supported and patched, disk encryption on, screen lock on, and separation of Company data from personal apps as directed.
- Loss or theft of any device used for Company work must be reported the same day (see Section 9).
6. Network Security: VPN, MFA, and Wi-Fi
- MFA everywhere. Multi-factor authentication is mandatory on all Company accounts — email, code hosting, cloud consoles, admin panels, and password manager. Authenticator apps or hardware keys are preferred over SMS.
- VPN. When accessing internal systems or when on any untrusted network, personnel must use the Company-approved VPN. VPN configuration must not be altered from the Company-managed settings.
- Home Wi-Fi. Home networks must use WPA2 or WPA3 encryption with a strong, unique passphrase; router admin passwords must be changed from factory defaults and router firmware kept updated. WEP or open (passwordless) home networks are not acceptable for Company work.
- Public Wi-Fi. Avoid public Wi-Fi where possible (prefer a personal hotspot). If public Wi-Fi is unavoidable, the VPN must be active before any Company system is accessed.
7. Protecting Company Data at Home
- Follow the clean-desk rules of the Physical Security Policy at home: lock screens when stepping away, keep confidential printouts locked away, and shred them when no longer needed.
- Work data belongs in Company-approved systems (our cloud drives, repositories, and applications) — never in personal cloud storage, personal email, or unencrypted USB drives.
- Household smart devices (voice assistants) should be kept out of earshot of confidential calls where practical.
- Downloading production data (customer records, financial data) to a local machine is prohibited unless explicitly approved, time-limited, encrypted, and deleted after use, in line with the Data Management Policy.
8. Out-of-House Hosting and Cloud Security
Remote work at Penusila Digital Solutions is safe by design because we keep data out of houses and in hardened clouds:
- Where systems live. Production workloads, databases, and backups are hosted with vetted providers — Amazon Web Services (AWS) for compute and storage, Cloudflare for the edge network, DNS, TLS, and DDoS/WAF protection, and Base44, our managed application platform (whose backend runs on AWS-based infrastructure) — in data centers independently audited under SOC 2 Type II and ISO 27001, with 24/7 physical security, redundant power, and environmental controls.
- Encryption. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 or provider-equivalent) across our products. Remote workers therefore access systems through encrypted channels end to end; no product data should ever need to sit unencrypted on a home device.
- Shared responsibility. Providers secure the physical and infrastructure layers; we secure what is ours — identity and access management, MFA on every console, least-privilege roles, key management, logging and monitoring, and secure configuration. We review provider security posture and our own configuration regularly, and we ensure the best security we practically can at every layer we control.
- Access. Administrative access to hosting consoles and production data is restricted to named individuals, protected by MFA, granted on least privilege, logged, and reviewed. Access is revoked immediately on role change or departure.
9. Incident Reporting
Report the following immediately, and in all cases within 24 hours:
- Lost or stolen devices, or suspected unauthorized access to a device or account.
- Phishing or social-engineering attempts targeting Company accounts.
- Accidental exposure of Company or customer data (wrong recipient, public link, unattended device).
- Any suspected compromise of home network or VPN credentials.
Fast reporting limits damage and is never punished; concealment or delayed reporting may be.
10. Expenses
The Company reimburses pre-approved, reasonable expenses required for secure remote work (such as necessary peripherals or security equipment) under its internal expense process.
11. Compliance and Enforcement
- Remote workers remain subject to all Company policies, including the Data Management Policy and Physical Security Policy.
- The Company may verify compliance (e.g., device encryption and patch status) through its endpoint management tooling.
- Violations may result in withdrawal of remote-work privileges and disciplinary action up to and including termination of employment or contract.
Related Policies
See also our Data Management Policy, Physical Security Policy, and Security & Data Protection overview. Questions can be sent to hello@penusiladigitalsolutions.org.