[Under the Hood] Debating the latest Tech and Tools for your Business

Watch Now

Security Policies

Effective Date: July 2026

Introduction

These policies establish how Salted Stone protects client information, its own systems, and the data it handles in the course of delivering services. They cover the confidentiality, integrity, and availability of that information.

Policy scope

These policies apply to all employees, contractors, and third parties with access to Salted Stone's systems, devices, and data.

Nature of our services, and how to read this policy

Salted Stone is a professional services firm providing strategy, implementation, development, and ongoing support on third-party marketing and CRM platforms, principally HubSpot.

Reading this policy correctly depends on four facts about how the firm operates. Salted Stone does not independently process, store, or control client personal information, and does not operate a data center, host production systems for clients, or provide software as a service. Access to client data is limited to client-directed activity inside client-controlled environments, such as the client's own HubSpot portal. Client data remains resident in the platform provider's infrastructure, where infrastructure security, encryption, physical security, network protection, redundancy, and disaster recovery are provided and certified by that provider. Access for Salted Stone personnel is provisioned, controlled, and revocable by the client through the platform's own administrative controls.

Every control described below is a control Salted Stone operates over its own systems, devices, and personnel. Controls over client data environments are governed by the platform provider's security program and by the client's configuration of that platform.

Security responsibility

The designated Security Owner, identified in Document control above, is accountable for this policy, for the annual security risk review, and for coordinating response to security incidents.

Information security

Data classification

Policy

All data handled by Salted Stone is classified according to sensitivity:

  1. Public data. Non-sensitive, non-confidential information.
  2. Internal data. Sensitive but not confidential information.
  3. Confidential data. Highly sensitive information, including client business information and any personal information accessed while delivering services.

Implementation

  • Data owners label and classify data at the point it is created or received.
  • Access controls and permissions align with the classification.
  • Confidential data is held only in access-controlled Google Workspace locations or within the client's own platform environment. It is not stored on local device storage, personal cloud accounts, or unapproved third-party tools.
  • Salted Stone does not accept, request, or knowingly process special categories of data, including medical records, payment card data, government identification numbers, or financial account information. An engagement that would involve such data is escalated before work begins.

Data handling

Policy

Data is handled according to its classification, and sensitive data is protected in transit and at rest.

Implementation

  • Unauthorized access to data is prohibited.
  • Encryption of client data at rest and in transit is provided by the platform hosting that data. Salted Stone does not generate, manage, escrow, or store cryptographic keys protecting client data. Key management is performed by those providers inside their own certified infrastructure.
  • Salted Stone business data resides in Google Workspace, which encrypts data at rest and in transit and maintains backup and recovery capability as part of its service.

Data retention and disposal

Policy

Client information is retained only as long as needed to deliver contracted services and to meet legal or contractual obligations.

Implementation

  • Salted Stone does not retain client personal information beyond the term of the engagement.
  • Working files are held in access-controlled Google Workspace locations, then archived or removed at engagement close.
  • On written request, and absent an overriding legal retention obligation, Salted Stone deletes or anonymizes client data in its possession and confirms completion to the client.
  • Access to client platform environments is relinquished at engagement close.
  • Devices are securely wiped before reassignment or disposal.

Remote work security

Policy

Personnel working remotely follow the protocols below to protect data and systems.

Implementation

  • Use company-provided or company-approved devices for work.
  • Use an encrypted connection when accessing company or client resources. Work is not performed over untrusted public networks without one.
  • Report lost or stolen devices immediately.

Endpoint and device security

Policy

Every device used to access Salted Stone or client systems meets a defined minimum standard.

Implementation

  • Full-disk encryption is required on all company-provided and company-approved devices used to access Salted Stone or client systems, so that the volume encryption key is bound to user authentication rather than to the device alone. Compliance is confirmed at device issue and during the annual security review.
  • Operating systems and browsers are configured for automatic security updates, so that critical and high-severity patches apply through vendor update channels without manual intervention.
  • Platform-native malware and threat protection is enabled on all devices.
  • Devices lock automatically after a period of inactivity and require authentication to unlock.
  • Salted Stone does not operate centrally managed endpoint detection and response tooling, centralized log aggregation, or mobile device management. These appear in the Security roadmap below.

Asset and platform inventory

Policy

Salted Stone maintains an inventory of the devices and platforms used to deliver services.

Implementation

  • A device inventory records company-provided devices and their assignment.
  • A platform inventory records the software platforms used in client delivery, the business purpose of each, and the individual accountable for administering access to it.
  • Both inventories are reviewed at least annually, and on material change.

Physical security

Policy

Salted Stone operates as a distributed organization and holds no facility in which client data resides.

Implementation

  • Salted Stone does not maintain a data center, server room, or other facility storing, transmitting, or processing client data. That data sits in the certified facilities of platform providers.
  • Personnel are responsible for the physical security of their assigned devices, including not leaving them unattended in unsecured locations, and reporting loss or theft immediately.

Network security

Policy

Salted Stone does not operate a network in which client data is stored, transmitted, or processed.

Implementation

  • Access to client platform environments occurs over encrypted connections from approved devices.
  • Host-based firewalls are enabled on company-provided devices.
  • Network segmentation, perimeter protection, and intrusion detection for client data environments are provided by the platform providers as part of their certified security programs.

Access control

User accounts

Policy

Accounts are created, maintained, and removed under defined controls.

Implementation

  • Strong passwords are required.
  • Multi-factor authentication is required on all Salted Stone Google Workspace accounts, and is enabled on client platform accounts wherever the platform supports it.
  • Access is reviewed and revoked for personnel who no longer require it.
  • Shared credentials are not used. Where a platform does not support individual named accounts, the exception is documented and approved by the Security Owner.
  • Credentials are stored only in an approved password manager, never in documents, spreadsheets, email, or chat.

Role-based access control

Policy

Access to systems and data follows role and responsibility.

Implementation

  • Personnel hold the least privilege their role requires.
  • Access to a client environment is granted only to personnel assigned to that engagement, at the permission level the role requires.
  • Access rights are reviewed at least annually, and on any change of role or engagement assignment.

Authentication and authorization

Policy

Access is granted on the basis of role and documented approval, and authenticated before it is granted.

Implementation

  • Password policy and multi-factor authentication are enforced as described above.
  • Authorization for access to a client environment is recorded, so that the basis for each person's access is auditable.

Onboarding and offboarding

Policy

Access is provisioned on a documented basis at hire and removed promptly on departure.

Implementation

  • Access is provisioned by role, at least privilege.
  • On termination or resignation, Salted Stone accounts are suspended and access to Salted Stone and client systems is revoked within 24 hours of the effective end of employment.
  • Where a departing individual held access to a client platform environment, the client is notified so that they can confirm removal in their own administrative controls.
  • Company-provided devices are returned and securely wiped.
  • Employees and contractors are bound by written confidentiality obligations that survive the end of their engagement.

Personnel screening

Policy

Salted Stone does not conduct criminal background screening as a standard practice.

Implementation

  • Where a client contractually requires screening for the personnel assigned to their account, Salted Stone accommodates that requirement for named personnel, subject to individual consent and applicable law, with screening costs borne by the client.
  • Requests of this kind are handled during contract negotiation rather than at the point of delivery.

Security awareness

Security training

Policy

All personnel receive security training at onboarding and at least annually thereafter.

Implementation

  • Training covers phishing and social engineering, credential practice, safe handling of client data, acceptable use of AI tools, and how to report a suspected incident.
  • The Security Owner records completion.

Email security

Policy

Inbound and outbound email is protected against malicious content.

Implementation

  • Google Workspace filters inbound email for spam, phishing, and malicious attachments and links.
  • Sender authentication is configured on Salted Stone sending domains.
  • Personnel report suspected phishing rather than interacting with it.

Use of artificial intelligence tools

Policy

Salted Stone uses AI and large language model tools in client delivery. They carry the same data handling obligations as any other platform.

Implementation

  • Only approved AI tools are used with client information. Approval requires that the provider does not train models on submitted business data by default, or that training has been disabled on the Salted Stone account.
  • Client confidential information is not submitted to consumer-grade or unapproved AI services.
  • A qualified team member reviews AI-assisted output before it is delivered to a client or published.
  • AI tools appear in the platform inventory, and in the subprocessor register where they access client information.

Incident response

Policy

Incidents are reported, escalated, and documented.

Incidents team members may encounter include:

  • Security breaches of websites, most commonly WordPress
  • A major bug discovered on a live website
  • Flaws discovered in a workflow automation
  • A previously working integration found to have broken
  • Suspected unauthorized access to a Salted Stone or client account
  • Loss or theft of a device with access to Salted Stone or client systems
  • Suspected exposure or misdirection of client confidential information

Implementation

  • Notify the relevant manager immediately.
  • The manager reviews the incident with any team members holding contextual information. Where a significant incident could affect clients or the agency itself, escalation goes immediately to the regional General Manager.
  • The Security Owner is notified of any incident involving suspected unauthorized access to, or exposure of, client data or personal information.
  • The client point of contact is notified as soon as enough information exists to describe the situation: what happened, what the impacts appear to be, and what is being done, or what Salted Stone recommends be done where it lacks the authority or resources to act alone.
  • Where an incident involves unauthorized access to, disclosure of, alteration of, or destruction of personal information within systems Salted Stone controls, the affected client is notified without undue delay and within 72 hours of Salted Stone becoming aware of it, consistent with Salted Stone's Data Protection Agreement.
  • Salted Stone assists the client in investigating and mitigating the incident. Responsibility for notifying data subjects or regulators rests with the client as data controller, unless Salted Stone is independently required by law to do so.

On resolution, a written breakdown of the incident timeline, actions taken, downstream effects, and resulting changes is provided to the client and to internal stakeholders. The Security Owner retains that documentation and reviews it during the annual security risk review, so that recurring causes are identified and addressed.

Service continuity

Policy

Salted Stone maintains the ability to keep delivering contracted services through a disruption.

Implementation

Salted Stone hosts no production infrastructure on behalf of clients. Client systems and the data in them sit on enterprise cloud platforms, including HubSpot and Google Workspace, which maintain their own redundancy, backup, and disaster recovery programs and publish their own resilience certifications. Salted Stone therefore operates no client-facing system requiring independent failover.

Continuity of Salted Stone's own delivery rests on several structural facts. The workforce is distributed, with no dependency on a single office or location. Working files are held in Google Workspace rather than on local device storage, so work in progress survives the loss of a device and remains accessible to authorized colleagues. Administrative access to each of Salted Stone's own critical platforms is held by more than one individual. Engagements are staffed so that knowledge of an engagement is not held by one person alone, with account records maintained in Salted Stone's CRM and project systems. Regional teams across multiple time zones permit cross-regional support where an engagement requires coverage.

Salted Stone does not conduct independent disaster recovery testing of client platforms, because those platforms are operated and tested by the providers named above. Salted Stone does not maintain a formally audited business continuity program of the kind expected of infrastructure or software providers. The Security Owner reviews this continuity approach at least annually, and after any material disruption. Salted Stone maintains a separate Business Continuity Plan, available to clients and assessors on request.

Security risk review

Policy

Salted Stone reviews its security posture on a defined cycle.

Implementation

  • At least annually, the Security Owner conducts and documents a security risk review. It covers threats to Salted Stone systems and to client data Salted Stone accesses, the platforms and AI tools in use and their security posture, access rights across Salted Stone and client environments, incidents recorded during the period, and progress against the Security roadmap.
  • Each identified risk is recorded with an owner and a remediation action.
  • The review goes to leadership, and its findings drive the annual update of this policy.

Vendor management

Vendor security assessment

Policy

Platforms and vendors with access to client or company data must meet defined security standards.

Implementation

  • A platform's security posture is evaluated before it is used in client delivery. Evaluation rests principally on the provider's independent certifications and audit reports, such as SOC 2 Type II and ISO 27001, alongside its published security documentation and its data processing terms.
  • Security requirements are included in vendor contracts.
  • Salted Stone's principal subprocessors in client delivery are HubSpot and Google Workspace. A subprocessor register records each provider, its purpose, the categories of data it may access, and its certifications. The register is available to clients on request.
  • Clients are informed before a new subprocessor with access to their data is added or replaced.
  • The register is reviewed at least annually during the security risk review.

Compliance

Regulatory compliance

Policy

Personnel comply with applicable laws and regulations, including regional data privacy requirements such as GDPR and CCPA, both in Salted Stone's own operations and in work performed for clients.

Implementation

  • Policies are reviewed and updated to reflect regulatory change.
  • Salted Stone enters into a Data Protection Agreement with clients, establishing the parties' respective roles, security obligations, breach notification commitments, and subprocessor terms. It is available on request.
  • Salted Stone holds no SOC 2, ISO 27001, or ISO 27701 certification, and relies on the certifications of the platform providers hosting client data. The Security roadmap below addresses this.

Reporting security incidents

Policy

Security incidents are reported promptly.

Implementation

  • Personnel report suspected incidents immediately. Reporting in good faith carries no penalty, including where the report proves unfounded or where the person reporting contributed to the incident.
  • Clients and third parties may report a suspected security concern to security@saltedstone.com.

Security roadmap

Salted Stone maintains a roadmap of security capabilities under development, so that clients and prospective clients can see both the current posture and its direction. Capabilities Salted Stone does not currently operate, and has under active consideration:

  • Centrally managed endpoint detection and response
  • Mobile device management for company-provided devices
  • Centralized log aggregation and alerting
  • Recurring authenticated vulnerability scanning
  • Independent external penetration testing
  • Third-party attestation of the control environment

The roadmap is reviewed during the annual security risk review.

Policy review and revision

Policy

This policy is reviewed at least annually.

Implementation

  • The Security Owner performs the review and leadership approves it.
  • Version, effective date, and last reviewed date in Document control are updated at every review, whether or not the content changes.
  • Material changes are communicated to all personnel.

Enforcement

Policy

Non-compliance with these policies may result in disciplinary action.

Implementation

  • Consequences for policy violations are communicated clearly and enforced consistently.

Contact

Questions about this policy, and requests for supporting documentation, go to security@saltedstone.com.