Purpose and scope
This policy applies to all Coopsphere personnel, contractors and systems used to build and operate the platform.
Access management
- Access is granted on a least-privilege basis and tied to a named individual.
- Administrative access to production systems is limited to personnel who require it.
- Access is reviewed periodically and revoked promptly when responsibilities change or end.
- Multi-factor authentication is required for administrative access where the provider supports it.
Data handling
- Customer data is used only to operate and support the service.
- Production data is not copied into development environments.
- Credentials and secrets are stored in a managed secret store, never in source code.
Change management
Changes are reviewed before release, tracked in version control, and can be rolled back. Dependencies are monitored and updated when security issues are identified.
Personnel
Personnel are bound by confidentiality obligations and receive guidance on secure handling of customer information. Suspected policy breaches are handled through the incident-response process.
This document describes how Coopsphere is operated by ASH Global Network Ltd. It is not legal advice and does not assert any third-party certification or audit outcome. For questions, contact support@coopsphere.org.