Skip to main content
The Physical Security Policy protects the equipment and physical media that botBrains personnel use, and defines how botBrains relies on certified providers for data center physical security. botBrains is fully remote with no office and no self-operated infrastructure, so physical security splits into two layers: the home-office and device controls botBrains operates directly, and the data center controls inherited from infrastructure providers.
botBrains is not yet ISO 27001 certified. We are preparing our ISMS and writing these policies as part of pursuing certification, and we fully intend to get our controls attested.

Scope

This policy applies to both botBrains team members, all devices they use to access botBrains systems or data, and the locations from which they work. It also covers the inherited physical security of the cloud infrastructure that hosts production data. botBrains operates no offices, server rooms, badge readers, or visitor logs of its own, so traditional perimeter controls don’t apply.

Home-office and remote-work security

Personnel work from home or another private, trusted location. botBrains doesn’t claim controls it can’t enforce, such as building access systems, but personnel must apply the following.

Device handling and media

Laptops are the primary endpoints, and the Asset Management Policy tracks them as assets. botBrains avoids storing production data on endpoints; work happens against cloud systems. botBrains doesn’t use removable media for production data. When a device reaches end of life or changes hands, botBrains securely erases its storage or destroys the encryption keys before disposal or reassignment.

Data center physical security (inherited)

botBrains stores and processes all production data in third-party cloud data centers and doesn’t operate any physical processing facility. Physical security of those facilities, including perimeter control, access logging, surveillance, fire suppression, climate control, and power redundancy, remains the providers’ responsibility, and their independent certifications cover it. botBrains relies on these certifications as evidence of data center physical security and doesn’t duplicate or re-attest these controls. botBrains assesses provider assurance as part of the Supplier Management Policy, and the full infrastructure map lives in the subprocessor list.

Enforcement

Personnel who don’t follow this policy are subject to corrective action. Personnel must report suspected unauthorized physical access to any device or to botBrains data immediately, and botBrains handles it as an incident.

ISO 27001 mapping

Review

The CISO owns this policy and reviews it at least annually and whenever a hosting provider, device fleet, or remote-work arrangement changes materially.