Information Security Policy

Last updated: September 12, 2026

Boon's Information Security Policy defines the requirements that maintain the security, confidentiality, integrity, and availability of Boon applications, systems, infrastructure, and data. It applies to all personnel acting on behalf of Boon, who are required to read, accept, and follow it on joining and at least annually thereafter.

What it covers

  • People security: candidate screening, background checks, confidentiality agreements, and security awareness training

  • System access security, least privilege, account audits, and password requirements

  • Asset security, data management, classification, retention, and disposal

  • Change and development management, environment separation, and source code control

  • Logging and monitoring, with logs retained for a minimum of one year

  • Business continuity, backup, and security incident response

  • Risk management, vendor management, and privacy

Last updated May 2026.

View the Information Security Policy (PDF)