RxMart Inc.
Information Security Policy
Company-wide security policy for RxMart Inc. — written to satisfy payment processor diligence and cyber insurance underwriting
Version 1.0 — DRAFT — July 30, 2026 | Items marked [GAP] are not yet implemented and must be built or honestly restated before this is provided to a third party
1. Purpose and Scope
RxMart Inc. operates a business-to-business marketplace for licensed pharmacies and a listing platform for licensed wholesale distributors. The company holds member licensure records, beneficial ownership information, government-issued identification for authorized signers, banking and payout destination details, and transaction records covering a substantial volume of regulated drug commerce. It does not hold protected health information.
This Policy applies to all RxMart employees, contractors, and third parties with access to RxMart systems or data, and to all systems, applications, devices, and data used to operate the business.
2. Governance and Ownership
Role | Responsibility |
|---|---|
Policy owner — [NAME / TITLE, to be designated] | Owns this Policy, approves exceptions, reports to the CEO |
Engineering lead | Implements technical controls, manages access provisioning, patching, logging, and secure development |
Compliance Officer — [NAME, to be designated] | Coordinates regulatory notification, vendor risk, and audit response |
Finance / Controller | Owns disbursement controls, segregation of duties, and reconciliation |
All personnel | Comply with this Policy and report suspected incidents immediately |
[GAP — designate the policy owner and Compliance Officer by name. This is the first thing a reviewer checks.]
- This Policy is reviewed at least annually and on any material change in systems, data handled, or applicable law.
- Exceptions require written approval from the policy owner, with a stated compensating control and expiry date, and are logged.
3. Data Classification and Handling
Class | Examples | Handling |
|---|---|---|
Restricted | Government ID images, bank account and payout details, beneficial ownership records, screening results, authentication credentials | Encrypted at rest and in transit; access on documented business need only; access logged; never emailed; never stored on endpoints |
Confidential | Member licensure records, transaction and pricing data, contracts, acceptance records, internal financials | Encrypted at rest and in transit; role-based access; not shared externally without authorization |
Internal | Operational documents, non-public analytics, internal communications | Access limited to personnel; not published |
Public | Marketing material, published policies, published fee pages | No restriction |
- Restricted data is not transmitted by email or SMS. The published Terms & Conditions state this to members and it applies internally as well.
- Production data is not copied to development or test environments. Where test data derived from production is required, it is anonymized first. [GAP — confirm current practice.]
4. Access Control
- Access is granted on least privilege and business need, approved by the system owner, and documented.
- Multi-factor authentication is mandatory for all RxMart accounts and for all member accounts, and is enforced rather than optional for any user with listing, purchasing, payout, or administrative privileges.
- Administrative and production access is restricted to named individuals, is reviewed [quarterly], and is separate from day-to-day user accounts.
- Shared or generic accounts are prohibited. Where a shared service account is unavoidable, credentials are stored in the password manager and ownership is assigned to a named individual.
- Joiners, movers, and leavers: access is provisioned on documented approval at hire, adjusted within [two (2) business days] of a role change, and revoked within [twenty-four (24) hours] of separation, including email, code repositories, cloud consoles, payment processor, and banking.
- Passwords are managed through an approved password manager. Credentials are never stored in code, configuration files, spreadsheets, or shared documents.
- Segregation of duties: no single individual may both add or modify a disbursement destination and release funds to it. Disbursements above [$______] require dual approval.
5. Payment and Financial Controls
These controls exist because the company directs the movement of a significant volume of member funds and because insider misappropriation is a named risk.
- Payout destination and connected account changes require re-authentication, out-of-band confirmation with a contact of record using details already on file, a hold of [24 to 72] hours, and notification to every account administrator.
- All changes to disbursement destinations are written to an immutable audit log capturing actor, timestamp, prior value, new value, and source IP.
- Platform gross transaction volume is reconciled to payment processor settlement and to the bank on a [monthly] cadence, with documented investigation and sign-off of variances. [GAP — confirm this is performed and documented.]
- Access to the payment processor dashboard and to banking is restricted to named individuals, uses multi-factor authentication, and is reviewed [quarterly].
- Vendor and payee additions require documented approval, a W-9, and verification of account ownership against the legal entity name.
6. Encryption
- All data in transit is encrypted using TLS 1.2 or higher. Plaintext protocols are disabled.
- All data at rest, including databases, object storage, and backups, is encrypted using AES-256 or equivalent.
- Encryption keys are managed through the cloud provider’s key management service, with access restricted and rotation at least [annually].
- Full disk encryption is required on every laptop and workstation with access to company systems.
7. Endpoint and Network Security
- Company and personal devices used for work must have full disk encryption, automatic screen lock, current operating system patches, and endpoint protection installed. [GAP — confirm whether endpoint management is deployed.]
- Production infrastructure is segmented from corporate systems. Administrative access to production is through [VPN / bastion / identity-aware proxy — CONFIRM] and is logged.
- Default deny on inbound network access; only required ports and services are exposed.
- Public cloud storage buckets containing Restricted or Confidential data are private by default and audited [quarterly] for exposure.
8. Vulnerability and Patch Management
- Critical security patches are applied within [seven (7) days] of release; high within [thirty (30) days]; others on the standard maintenance cycle.
- Dependency scanning runs on every build, and known critical vulnerabilities block deployment.
- External vulnerability scanning runs [quarterly]. [GAP — confirm whether this is in place.]
- An independent penetration test is performed [annually] with findings tracked to closure. [GAP — not yet performed; commit to a date or state as planned.]
9. Secure Development
- All code changes are peer reviewed before merge. Direct commits to production branches are prohibited.
- Secrets are managed through a secrets manager and never committed to source control. Repositories are scanned for committed secrets.
- Development, staging, and production environments are separated, with separate credentials.
- Changes to authentication, authorization, payment, or verification logic require a second reviewer and are recorded in the change log.
10. Logging and Monitoring
- The following are logged at minimum: authentication successes and failures; administrative actions; access to Restricted data; changes to member licensure, verification status, and disbursement destinations; and all fund movements.
- Logs are tamper-resistant, retained for not less than [two (2) years], and access to them is itself logged.
- Alerting is configured for repeated authentication failure, privilege escalation, disbursement destination change, unusual disbursement volume, and access to Restricted data outside normal patterns. [GAP — confirm which alerts are live.]
11. Backup and Recovery
- Production data is backed up [daily], encrypted, and stored separately from production.
- Backups are tested by restoration at least [semi-annually], with results recorded. [GAP — confirm whether restoration testing has been performed.]
- Recovery time objective: [__] hours. Recovery point objective: [__] hours.
12. Third-Party and Vendor Risk
- Vendors with access to Restricted or Confidential data are assessed before engagement, covering their security posture, breach history, subprocessors, and contractual security commitments.
- Critical vendors are reviewed [annually]. The current critical set includes the payment processor, cloud hosting provider, verification and screening providers, email provider, and the partner integrations surfaced in the member dashboard.
- Contracts with vendors handling Restricted data must include confidentiality, security, breach notification, and audit or evidence rights.
- A current inventory of vendors, the data each accesses, and the review date is maintained. [GAP — build the inventory.]
13. Personnel Security
- Background screening is conducted for personnel with access to Restricted data or disbursement authority, subject to applicable law including the Fair Credit Reporting Act where a consumer report is obtained.
- All personnel acknowledge this Policy at hire and annually.
- Security awareness training is delivered at hire and annually, and covers phishing, social engineering, credential handling, and incident reporting. Given that funds transfer fraud and social engineering are the company’s most likely loss events, training specifically covers payment redirection and vendor impersonation attempts.
- Disciplinary process applies to Policy violations, up to termination.
14. Physical Security
- Company systems are cloud hosted; physical security of production infrastructure is the responsibility of the hosting provider, whose relevant attestation is obtained and reviewed annually.
- Devices holding company data must be secured when unattended and must not be left in vehicles or checked luggage.
- Printed material containing Restricted or Confidential data is shredded when no longer required.
15. Incident Reporting
- All personnel must report suspected security incidents immediately to [SECURITY NOTICE EMAIL] and to the policy owner. Reporting in good faith never results in disciplinary action, including where the reporter contributed to the incident.
- Members report suspected account compromise to the same address, as stated in the Terms & Conditions.
- Handling is governed by the RxMart Incident Response Plan.
16. Retention and Disposal
- Data is retained per the schedule published in the Privacy Policy and required by the member agreements: transaction and tracing records not less than six years; verification files for the term of membership plus six years; system and access logs not less than two years.
- Data past its retention period is securely deleted unless subject to legal hold.
- Media and devices are securely wiped or destroyed before disposal or reassignment, with a record kept.
17. Compliance and Assurance
- Compliance with this Policy is reviewed [annually], with findings reported to the CEO.
- Evidence of control operation is retained so that it can be produced to a payment processor, insurer, auditor, or regulator on request.
- [GAP — consider whether a SOC 2 Type I or Type II report is warranted. A processor or enterprise pharmacy chain will eventually ask, and the lead time is months, not weeks.]
Policy owner: [NAME / TITLE]
Approved by: [CEO]
Effective date: [EFFECTIVE DATE]
Review cycle: Annually and on material change
Version: 1.0