This policy defines how Cortena classifies data and what controls apply to each class.
1. Purpose
To ensure data is protected according to its sensitivity.
2. Scope
Applies to all data handled by Cortena (customer data and internal data).
3. Classification levels
3.1 Public
Information intended for public release (for example marketing website content).
3.2 Internal
Operational information not meant for public distribution (for example internal process docs).
3.3 Confidential
Business-sensitive information (for example contracts, pricing, internal architecture details).
3.4 Restricted
Highest sensitivity. Includes:
- customer financial data (invoices, transaction references)
- credentials and secrets
- access logs with sensitive context
- any regulated personal data in customer documents
4. Handling requirements
- Restricted data must be encrypted at rest and in transit.
- Access to Restricted data must be limited (RBAC, least privilege) and monitored.
- Restricted data must not be shared externally without authorization and a valid purpose.
5. Review and updates
Reviewed periodically or upon material change to data handling practices.