KONTYRA Legal

Access Control Policy

This Access Control Policy defines how KONTYRA grants, reviews, protects, changes, and removes access to company-managed systems, services, repositories, infrastructure, and data.

1. Purpose

The purpose of this policy is to ensure that access is authorized, appropriate, auditable, and removed when no longer needed. Access controls help protect KONTYRA systems, customers, intellectual property, and operational integrity.

2. Scope

This policy applies to:

  • Production systems, administrative consoles, cloud infrastructure, code repositories, internal tools, and support systems.
  • Employees, contractors, contributors, service accounts, automation, vendors, and third-party integrations.
  • Credentials including passwords, SSH keys, API keys, access tokens, recovery codes, secrets, and privileged session tokens.

3. Access Principles

  • Least privilege: users and services receive only the access needed to perform approved duties.
  • Need to know: sensitive data is available only to users with a legitimate business or operational need.
  • Separation of duties: high-risk actions should be divided or reviewed where practical.
  • Unique accountability: shared human accounts should be avoided; activity should be attributable to individual users or approved services.
  • Secure lifecycle: access is requested, approved, provisioned, reviewed, changed, and revoked through controlled processes.

4. Access Requests and Approval

Access must be requested for a defined role, project, support need, or operational duty. Requests should identify the user or service, system, permission level, reason, duration, and approver. Elevated access requires approval from an authorized owner or administrator.

5. Authentication Requirements

  • Administrative and sensitive accounts should use multi-factor authentication where supported.
  • Passwords must not be reused across unrelated systems and must be stored only in approved password or secret management tools.
  • Credentials, tokens, and keys must not be committed to source code, shared in public channels, or stored in unsecured files.
  • Service accounts must have defined owners, scoped permissions, and rotation or review procedures appropriate to risk.

6. Privileged Access

Privileged access to production, infrastructure, billing, identity, repository, and security systems must be limited, monitored where feasible, and used only for approved administrative purposes. Users should use non-privileged accounts for routine work when practical.

7. Access Reviews

KONTYRA will periodically review access to sensitive systems and remove or adjust access that is no longer needed, excessive, dormant, or inconsistent with a user's current role. Reviews may be risk-based and more frequent for production or privileged systems.

8. Joiner, Mover, and Leaver Process

  • Joiners: access is granted after authorization and limited to current responsibilities.
  • Movers: access is adjusted when a role, project, or responsibility changes.
  • Leavers: access is revoked promptly when employment, contract work, vendor access, or project participation ends.

9. Monitoring and Violations

KONTYRA may monitor access activity to detect unauthorized use, excessive permissions, credential misuse, or policy violations. Violations may result in access revocation, account suspension, disciplinary action, contract remedies, or legal escalation.