Security Addendum — postal.ID

This addendum describes baseline security commitments for the Services. Detailed TOMs are in the DPA Annex 2.

1

1. Access controls

  • RBAC with least privilege.
  • MFA for admin roles (recommended/required).
  • Audit logs for key actions (case creation, evidence download, policy changes).
2

2. Encryption

  • Encryption in transit (TLS).
  • Encryption at rest for sensitive data.
  • OTPs stored hashed (not plaintext).
3

3. Logging and monitoring

  • Centralized logs, alerting, and anomaly detection for production.
  • Retention aligned to security needs and privacy requirements.
4

4. Vulnerability management

  • Regular patching and dependency management.
  • Penetration testing cadence: [annual] (or as committed).
5

5. Incident response

  • Documented incident response plan.
  • Customer notifications per DPA.
6

6. Business continuity

  • Backups and disaster recovery procedures.
  • Recovery targets: [RPO/RTO placeholders].
7

7. Subprocessor security

  • Due diligence and contractual controls for subprocessors.