DNZ Consulting LLC · Effective August 27, 2026 · Next review August 27, 2027
This policy states who may reach a system at DNZ Consulting LLC, and how we grant and remove that access.
1. Scope and ownership
This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.
The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.
2. Least privilege
Grant the smallest permission that lets the person do the work.
Grant access to personal data only when the task needs that data.
Do not use an administrator account for daily work.
Do not share an account. Every person uses their own account.
Request the narrowest scope when you authorize an application on a third-party platform.
3. Database access
Row Level Security stays on for every table that holds user data.
An application uses a restricted key. It never uses an administrative key.
We use an administrative key only for a named maintenance task, and never from client code.
4. Granting access
The Managing Member approves every access request.
We record what we granted, to whom, and why.
Access to production data needs a written business reason.
5. Removing access
Remove access on the last day of the work.
Remove access immediately after a suspected compromise.
Rotate every shared credential that the person could reach.
6. Review
We review every account and every permission every 6 months.
We remove an account that nobody has used for 90 days.
We review third-party application authorizations at the same time. We revoke the ones we no longer use.