Skip to main content
The Data Classification Policy is the canonical scheme for how botBrains classifies, labels, and handles information by sensitivity. It assigns every piece of data to one of four levels so that each receives a proportionate level of protection across its lifecycle, from creation to deletion.
botBrains is not yet ISO 27001 certified. We are preparing our ISMS and writing these policies as part of pursuing certification, and we fully intend to get our controls attested.

Scope

This policy applies to all information that botBrains creates, receives, stores, or transmits in any form (electronic or physical), and to every system that processes it. A system inherits the classification of the highest-sensitivity data it holds.

Classification levels

botBrains uses four levels. When the level isn’t obvious, choose the higher one.

Labeling

Repository and platform context establishes the level for most data: GitHub private repositories hold Confidential source code, the production multi-tenant database and object storage hold Customer Data, and the shared password manager holds Confidential secrets. Personnel apply an explicit “Confidential” label only when a document leaves its default context, for example a security report shared outside the platform.

Handling rules

Handling requirements increase with sensitivity. The Cryptography Policy defines encryption standards once; retention periods and secure deletion live in the Data Retention Policy. botBrains processes Customer Data only within the EU, using the subprocessors listed at Subprocessors, with no transfer to a third country.

Exceptions and enforcement

The CISO approves any exception to this policy and records it in the risk register. Personnel report suspected mishandling to the CISO. Violations can lead to revoked access and disciplinary action under the Code of Conduct.

ISO 27001 mapping

This policy supports Annex A 5.12 (classification of information), 5.13 (labelling of information), 5.14 (information transfer), 8.10 (information deletion), 8.11 (data masking), and 8.12 (data leakage prevention).

Review

The CISO owns this policy and reviews it at least annually and on any material change.