Information Security Policy

Chesed Projects · CC Charges Tracker · Effective: June 25, 2026 · Review: annually

This Information Security Policy ("ISP") defines how Chesed Projects protects the confidentiality, integrity, and availability of consumer financial data processed by the CC Charges Tracker application. It applies to all personnel and systems that store, process, or transmit this data.

1. Scope & Ownership

The policy covers the application, its server, database, and supporting infrastructure. The application owner (mkantor@mkantor.com) is responsible for maintaining and enforcing this policy and reviewing it at least annually.

2. Data Classification

Financial account and transaction data accessed via Plaid is classified as Confidential and is subject to the strongest controls in this policy.

3. Encryption

4. Access Control

Access requires individual authentication with multi-factor authentication (MFA) and follows least-privilege and role-based principles, as detailed in the Access Control Policy.

5. Application Protections

6. Vulnerability & Patch Management

Operating-system security updates are applied automatically. Identified vulnerabilities are remediated within a defined service-level agreement (SLA): critical within 7 days, high within 30 days. Periodic vulnerability scans are performed on the server.

7. Logging & Monitoring

Security-relevant events (logins, link attempts, errors) are logged with timestamps and retained for review. Logs are protected from unauthorized modification.

8. Incident Response

Suspected security incidents are investigated promptly. If consumer data is affected, we contain the issue, assess impact, notify affected parties and relevant providers (including Plaid) as required, and document remediation.

9. Data Retention

Data is retained and deleted per the Data Retention & Deletion Policy.