Security & Governance
Information Security Policy
Last Updated: August 21, 2026
Security is our profession — so we hold our own environment to the standard we set for clients. This Information Security Policy states how WatchUr6, Inc. protects the confidentiality, integrity, and availability of the information assets entrusted to us. It reflects the operational discipline behind our audit readiness work: we practice what we preach.
1.0 Purpose and Policy Statement
This Information Security Policy (ISP) establishes the framework for protecting the information assets of WatchUr6, Inc., its employees, and — most importantly — its clients. As a veteran-owned provider of audit readiness and related cybersecurity services, WatchUr6 is committed to the highest standards of information security.
Our policy is to protect the Confidentiality, Integrity, and Availability (the "CIA Triad") of all information assets against all threats, whether internal or external, deliberate or accidental. This policy provides the authority and direction for implementing and enforcing information security controls across the organization. The security of our own and our clients' data is paramount to our reputation, our legal and regulatory compliance, and the trust our clients place in us.
2.0 Scope
This policy applies to all WatchUr6, Inc. personnel — including full-time and part-time employees, contractors, consultants, temporary staff, and any third parties who have access to WatchUr6 or its clients' information assets.
It covers all information assets, including but not limited to:
- Data (client, corporate, employee) in any form — digital or physical.
- All computer and communication systems, networks, and applications owned or managed by WatchUr6.
- The WatchUr6 corporate website (www.watchur6.com and related properties).
- All physical facilities, including the corporate office in Folsom, California, and the United Kingdom office in Manchester.
3.0 Roles and Responsibilities
- Management. Provides clear direction, visible support, and adequate resources to implement and maintain this policy. Management holds ultimate responsibility for the security of WatchUr6's information assets.
- Chief Information Security Officer (CISO) / security lead. Responsible for developing, implementing, and maintaining the information security program, managing security incidents, conducting risk assessments, and ensuring compliance with this policy.
- All personnel. Responsible for understanding and complying with this policy and all supporting procedures. Every individual has a duty to protect the company and client data they handle and to report any suspected security incident immediately.
4.0 Data Classification and Handling
All data must be classified and handled according to its sensitivity. The following classifications apply:
- Level 3 — Client Confidential. The most sensitive classification. Includes all non-public client data, such as system configurations, vulnerability assessments, audit findings, incident-response data, network diagrams, intellectual property, and any data covered by compliance frameworks — including Protected Health Information (PHI) under HIPAA and Controlled Unclassified Information (CUI) under CMMC / NIST SP 800-171. Requires the highest level of protection: encryption at rest and in transit, strict access controls, and logging.
- Level 2 — WatchUr6 Confidential. Sensitive internal data that, if disclosed, could harm WatchUr6 — financial records, strategic plans, employee Personally Identifiable Information (PII), and proprietary internal processes. Requires strong protection and must not be shared outside the company without proper authorization.
- Level 1 — Internal. Data intended for internal use but not highly sensitive — internal communications, procedural documents, and general project information.
- Level 0 — Public. Information explicitly approved for public distribution — marketing materials, press releases, and public website content.
5.0 Access Control
Access to information systems and data is granted on the principles of Least Privilege and Need-to-Know.
- Authentication. All access to systems containing Client Confidential or WatchUr6 Confidential data must use strong authentication. Passwords must meet complexity requirements, and Multi-Factor Authentication (MFA) must be enabled wherever technically feasible.
- Authorization. Role-Based Access Control (RBAC) ensures personnel have access only to the information and systems required for their role.
- Access reviews. User access rights are reviewed at least quarterly, and immediately upon a change in role or termination.
- Onboarding / offboarding. Formal processes govern granting access to new personnel and revoking all access for departing personnel on their last day.
6.0 Acceptable Use of Technology
- Company-provided assets (laptops, phones, software) are for business purposes. Limited personal use is permitted provided it does not interfere with job performance or violate other policies.
- Personnel are prohibited from installing unauthorized software on company equipment.
- Use of company assets for any illegal, unethical, or malicious activity is strictly forbidden.
- Client Confidential data must not be stored on personal devices or transferred to non-approved cloud services (for example, personal Google Drive or Dropbox).
7.0 Network and System Security
- Network protection. The corporate network is protected by firewalls. All wireless networks must be encrypted using strong, industry-standard protocols.
- Remote access. All remote access to the corporate network or client environments must use a secure, company-approved Virtual Private Network (VPN) with MFA.
- Vulnerability and patch management. All systems are kept current with security patches. Regular vulnerability scans are performed on external and internal systems, and critical patches are applied within 30 days of release.
- Encryption. All company laptops must have full-disk encryption enabled. All Client Confidential data must be encrypted at rest and in transit using industry-standard algorithms (for example, AES-256 and TLS 1.2 or higher).
8.0 Website Security
The WatchUr6 public website is a business asset and is secured accordingly.
- Secure communications. The website enforces HTTPS (TLS 1.2 or higher) for all connections to encrypt data in transit.
- Data collection. Any form that collects personal or contact information is accompanied by a clear, accessible Privacy Policy, and the collected data is handled accordingly and protected as WatchUr6 Confidential.
- Vulnerability management. The website and its infrastructure are regularly scanned for vulnerabilities and maintained following secure coding practices to mitigate common risks such as the OWASP Top 10.
- Access control. Administrative access to the website's content management system is restricted to authorized personnel and requires MFA.
9.0 Incident Response and Business Continuity
As a firm whose clients depend on our resilience, we hold our own incident response and continuity to a high standard.
- Incident Response Plan (IRP). WatchUr6 maintains a formal IRP detailing how we identify, contain, eradicate, and recover from security incidents.
- Reporting. All personnel must immediately report any suspected security incident, weakness, or threat to the security lead.
- Business Continuity / Disaster Recovery (BCDR). A BCDR plan is maintained and tested at least annually so we can continue critical operations and client services through a significant disruption. This includes reliable backups of all critical data.
10.0 Physical and Environmental Security
- Facility access. Access to WatchUr6 offices — including the corporate office in Folsom, CA, and the UK office in Manchester — is controlled. A "clean desk" policy requires sensitive documents and removable media to be secured when unattended.
- Asset management. A formal inventory of all hardware and software assets is maintained.
- Secure disposal. All media — digital and physical — containing sensitive information is securely disposed of via methods such as shredding or cryptographic erasure.
11.0 Compliance
WatchUr6 is committed to complying with all applicable laws, regulations, and contractual obligations.
- Legal and regulatory. Including, but not limited to, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and — for individuals in the UK and EEA — the UK GDPR and EU GDPR, as described in our Privacy Policy.
- Client frameworks. As we guide clients through SOC 2, HIPAA, and CMMC / NIST SP 800-171, our internal security practices align with the principles and controls of those frameworks — so we practice what we preach.
- Security awareness training. All personnel receive security awareness training upon hiring and at least annually thereafter.
12.0 Policy Enforcement and Review
- Enforcement. Violation of this policy may result in disciplinary action, up to and including termination of employment or contract, and may lead to legal action.
- Policy review. This policy is reviewed at least annually, or upon any significant change to the business or threat landscape, to ensure its continuing relevance and effectiveness.
13.0 Contact Us
For questions about this Information Security Policy, or to report a security concern, contact us at:
WatchUr6, Inc.
- Phone+1 916-647-7553
- Email[email protected]
- Webwww.watchur6.com/contact
- Address1024 Iron Point Rd, Folsom, CA 95630, USA
Want this discipline applied to your environment? Book a strategy call and we'll map it to your audit.