Scope
This policy applies to both botBrains team members, all devices they use to access botBrains systems or data, and the locations from which they work. It also covers the inherited physical security of the cloud infrastructure that hosts production data. botBrains operates no offices, server rooms, badge readers, or visitor logs of its own, so traditional perimeter controls don’t apply.Home-office and remote-work security
Personnel work from home or another private, trusted location. botBrains doesn’t claim controls it can’t enforce, such as building access systems, but personnel must apply the following.Device handling and media
Laptops are the primary endpoints, and the Asset Management Policy tracks them as assets. botBrains avoids storing production data on endpoints; work happens against cloud systems. botBrains doesn’t use removable media for production data. When a device reaches end of life or changes hands, botBrains securely erases its storage or destroys the encryption keys before disposal or reassignment.Data center physical security (inherited)
botBrains stores and processes all production data in third-party cloud data centers and doesn’t operate any physical processing facility. Physical security of those facilities, including perimeter control, access logging, surveillance, fire suppression, climate control, and power redundancy, remains the providers’ responsibility, and their independent certifications cover it.
botBrains relies on these certifications as evidence of data center physical security and doesn’t duplicate or re-attest these controls. botBrains assesses provider assurance as part of the Supplier Management Policy, and the full infrastructure map lives in the subprocessor list.