Information Security Policy

Premmisus Inc.

Document version1.0
Effective date2026-05-10
Next review2027-05-10
OwnerElliott Cuthbert, Founder & Director
Contactelliott@premmisus.com

1. Purpose & scope

This policy establishes the information-security controls that govern the Mafia application (the “Application”) operated by Premmisus Inc. (“Premmisus”). It applies to all data collected, processed, transmitted, or stored by the Application, including financial data retrieved from third-party providers (Plaid Inc., Stripe Inc.) and operational data entered by the authorized user.

2. Roles & responsibilities

Premmisus is a single-founder company. The founder, Elliott Cuthbert, is the sole party responsible for information security. The founder is the data controller, system administrator, software developer, incident responder, and policy approver. There are no employees, contractors, or third-party developers with system access.

3. Data classification

4. Identity & access management

5. Encryption

The Application enforces a defense-in-depth encryption posture: all data is encrypted at rest at the storage layer, with an additional application-layer encryption envelope on the highest-sensitivity fields (third-party access tokens). All data in transit uses TLS 1.2 or higher.

6. Network & infrastructure security

7. Application security, SDLC & vulnerability management

7.1 Secure development

7.2 Vulnerability scanning

Premmisus operates an active vulnerability-detection program covering both production assets and the founder’s endpoint device:

7.3 Patching SLA

Identified vulnerabilities are patched within the following service-level commitments, measured from the time the vulnerability is identified by Dependabot, by a vendor advisory, or by independent observation:

SeverityExamplesPatching commitment
CriticalRCE, auth bypass, encryption-key disclosure, payment-path compromiseSame business day
HighPrivilege escalation, sensitive-data exposure, exploitable XSS / SSRFWithin 7 calendar days
MediumDoS in non-critical paths, information disclosure with limited impactWithin 30 calendar days
LowTheoretical findings, defense-in-depth improvementsBest-effort, bundled with the next planned release

Patches are applied by upgrading the affected dependency or configuration, validating against the Application’s TypeScript/Next.js build, and deploying via the standard CI/CD path. The Kill Switch (§7.1) is available as a containment control for any vulnerability that materially threatens real-money paths while a permanent patch is in flight.

7.4 End-of-life (EOL) software monitoring

8. Logging, monitoring & audit

9. Vendor & third-party management

Premmisus relies on the following third-party processors. Each is evaluated for security posture before adoption and is governed by its own contractual terms:

10. Data retention & deletion

11. Incident response

12. Backup & disaster recovery

13. Personnel security

Premmisus is a single-founder company. The founder is the only individual with system access. There are no employees, contractors, or third-party developers requiring background checks, access provisioning, or off-boarding.

14. Compliance & certifications

15. Policy review & approval

This policy is reviewed at least annually by the policy owner and updated as new controls are introduced or risk posture changes. Material changes are logged in the document version history below. The current version is approved and signed by:

Elliott Cuthbert, Founder & Director
Effective: 2026-05-10
Next review: 2027-05-10

16. Contact

Questions about this policy or about Premmisus’s security practices should be directed to elliott@premmisus.com.