Employee Center Data Security Policy
No Raw Database Data Claim
For clarity, this document does not claim that Quintin N. Mahan owns raw facts, raw database rows, independent outside source records, CRS-owned operational records, customer-owned records, third-party-owned records, or customer relationships merely because such information is entered into, stored in, processed by, displayed through, backed up with, or exported from EC.
This document protects EC Protected Materials: the application, software, source code, schemas, database design, data model, relationships, indexes, workflows, dashboards, reports, queries, automations, integrations, APIs, access controls, credentials, hardware, infrastructure, legal records, certificate records, hashes, metadata systems, audit systems, methods, processes, techniques, trade secrets, documentation, and EC-created structural organization.
Version: 1.0
Effective Date: June 1, 2026
Platform: Employee Center / EC
Owner: Quintin N. Mahan
Legal Hub: /legal
Policy URL: /legal/data-security-policy
1. Purpose
This Data Security Policy explains how Employee Center (“EC”) protects EC systems, EC accounts, EC data, EC credentials, EC legal records, EC certificates, EC backups, EC audit logs, EC infrastructure, and the EC Protected Materials.
EC is a private operational platform owned by Quintin N. Mahan. Access to EC is conditional, limited, revocable, and governed by the Employee Center Terms and Conditions.
This policy is intended to support confidentiality, integrity, availability, accountability, legal preservation, evidence preservation and authorized transition support, and protection of EC ownership.
2. Scope
This policy applies to:
- EC users;
- administrators;
- company-authority users;
- display accounts;
- service accounts;
- API accounts;
- integrations;
- automations;
- devices accessing EC;
- EC servers;
- EC databases;
- EC backups;
- EC legal records;
- EC certificates;
- EC exhibits;
- EC repositories;
- EC credentials;
- EC infrastructure.
This policy applies to EC access through browsers, dashboards, APIs, automations, webhooks, scripts, service accounts, database tools, admin tools, terminals, file shares, backups, and connected integrations.
3. Relationship to Other Policies
This policy works together with:
- Employee Center Terms and Conditions;
- Acceptable Use Policy;
- Privacy Notice;
- Cookie and Local Storage Notice;
- Data Retention and Backup Policy;
- API and Integrations Policy.
If this Data Security Policy conflicts with the Employee Center Terms and Conditions, the Terms and Conditions control unless Quintin N. Mahan signs a separate written agreement stating otherwise.
Nothing in this policy transfers ownership of EC, EC source code, EC data, EC backups, EC certificates, EC repositories, EC credentials, EC infrastructure, or the EC Protected Materials.
4. Security Principles
EC security is based on these principles:
- access should be limited to authorized users;
- users should have only the access they need;
- owner/admin access must be protected;
- credentials must be kept confidential;
- logs and audit records must be preserved;
- legal records and certificates must be protected from tampering;
- backups must be protected from deletion, corruption, or seizure;
- EC source code and infrastructure must remain controlled by Quintin N. Mahan;
- unauthorized access or use is prohibited.
5. Account Security
Each user is responsible for protecting their EC account.
Users must not:
- share passwords;
- share login sessions;
- reuse another user’s account;
- impersonate another user;
- bypass login controls;
- bypass Terms acceptance controls;
- bypass role permissions;
- save passwords on untrusted devices;
- leave EC open on shared devices;
- transfer account access to another person;
- use disabled or revoked accounts.
Users should report suspected account compromise promptly.
6. Passwords, Sessions, and Authentication
EC may use authentication controls to protect access.
These controls may include:
- passwords;
- session expiration;
- remember-me limits;
- CSRF protection;
- device/session review;
- account lockout;
- role checks;
- admin-only routes;
- company-authority checks;
- Terms acceptance checks;
- certificate access checks;
- API/service-account authentication.
EC may suspend, revoke, expire, or reset sessions, accounts, or credentials where needed for security, enforcement, or preservation.
7. Role-Based Access
EC may restrict access by:
- user role;
- authority level;
- admin status;
- company-authority status;
- assigned module;
- assigned task;
- route permission;
- API permission;
- integration permission;
- account type;
- owner/admin decision.
Users may not attempt to access modules, records, reports, dashboards, certificates, exports, admin tools, APIs, or integrations outside their authorized role.
8. Owner/Admin Access
Owner/admin access is required to operate, maintain, secure, preserve, audit, and defend EC.
Quintin N. Mahan may retain owner/admin access to:
- EC application;
- EC database;
- EC backups;
- EC repositories;
- EC infrastructure;
- EC logs;
- EC certificates;
- EC legal records;
- EC exhibits;
- EC credentials;
- EC integrations;
- EC service accounts;
- EC deployment systems.
No user or company may disable, revoke, seize, transfer, or interfere with owner/admin access except through lawful process.
9. Credentials, Tokens, and Keys
EC credentials must be protected.
Protected credentials include:
- passwords;
- API keys;
- OAuth tokens;
- SSH keys;
- database credentials;
- service-account credentials;
- webhook secrets;
- backup credentials;
- repository credentials;
- email credentials;
- Zoho credentials;
- Google credentials;
- Tailscale credentials;
- SMS/modem credentials;
- server credentials;
- device credentials.
Users may not copy, export, disclose, rotate, revoke, reset, or use EC credentials except as authorized by Quintin N. Mahan.
10. Database Security
EC databases may contain operational, customer, employee, audit, legal, certificate, and backup-related records.
Users may not access EC databases directly unless authorized.
Users may not:
- connect to the database outside approved tools;
- copy the database;
- dump the database;
- alter schemas without authorization;
- modify records outside approved workflows;
- delete audit records;
- delete acceptance records;
- delete certificate records;
- delete Terms versions;
- delete backup records;
- tamper with hashes;
- bypass application permissions through database access.
Database access may be logged, restricted, monitored, and reviewed.
11. Source Code and Repository Security
EC source code, repositories, deployment files, configuration files, migrations, scripts, automations, templates, certificate generators, report logic, dashboard logic, and integration code are protected EC materials.
Users may not:
- copy EC repositories;
- fork EC source code without authorization;
- remove ownership notices;
- publish EC code;
- transfer EC code to CRS, a buyer, a successor, or a third party;
- use EC code to build a competing system;
- use EC code after access is revoked;
- alter EC code to remove owner/admin access, legal records, certificates, logs, or Terms controls.
12. Backup Security
EC backups may include databases, files, attachments, legal records, Terms versions, policy versions, certificates, generated PDFs, logs, exhibits, configuration, and metadata.
Backups must be protected from unauthorized access, deletion, corruption, seizure, transfer, or lockout.
Users may not:
- delete EC backups;
- copy EC backups without authorization;
- move EC backups without authorization;
- take backup drives or storage;
- disable backup jobs;
- corrupt backup files;
- prevent Quintin N. Mahan from accessing EC backups;
- use backups to clone or seize EC.
13. Logging and Audit Security
EC may preserve logs and audit trails for security, troubleshooting, operations, evidence, legal defense, enforcement, and evidence preservation and authorized transition support.
Protected logs may include:
- login logs;
- failed login logs;
- session logs;
- IP address logs;
- user-agent logs;
- page access logs;
- record-change logs;
- export logs;
- API logs;
- webhook logs;
- automation logs;
- certificate access logs;
- Terms acceptance logs;
- decline logs;
- admin activity logs;
- security logs;
- error logs.
Users may not delete, alter, conceal, disable, or interfere with EC logs or audit trails.
14. Certificate and Legal Record Security
EC legal records are protected EC records.
Protected legal records include:
- Terms versions;
- policy versions;
- acceptance records;
- decline records;
- individual acceptance certificates;
- company acceptance certificates;
- Exhibit A;
- Exhibit B;
- Exhibit C;
- certificate PDFs;
- certificate hashes;
- Terms hashes;
- generated legal artifacts;
- legal email logs;
- legal audit metadata.
Users may not alter, delete, forge, backdate, conceal, corrupt, or interfere with EC legal records.
15. Device Security
Users should access EC only from devices that are appropriate for authorized EC work.
Users should not use EC from devices that are:
- compromised;
- infected with malware;
- shared without authorization;
- not under the user’s control;
- missing basic security protections;
- used to capture or steal credentials;
- used to copy EC records without authorization.
Users should sign out when finished, especially on shared or portable devices.
16. Network and Infrastructure Security
EC may rely on networks, routers, firewalls, reverse proxies, DNS, Tailscale, VPNs, local networks, cloud networks, storage systems, servers, Raspberry Pis, modems, APIs, and integrations.
Users may not interfere with EC infrastructure or network security.
Users may not:
- redirect EC domains;
- change EC routing;
- disable reverse proxies;
- change firewall rules without authorization;
- intercept EC traffic;
- interfere with Tailscale or VPN access;
- disable EC servers;
- disconnect EC devices;
- interfere with EC storage;
- interfere with monitoring;
- use network access to bypass EC permissions.
17. API, Webhook, and Integration Security
EC APIs, webhooks, automations, and integrations must be used only as authorized.
Users may not:
- share API keys;
- misuse service accounts;
- send forged webhook data;
- overload EC with automated requests;
- bypass EC permissions through APIs;
- export records through unauthorized scripts;
- use integrations to copy EC data into unauthorized systems;
- disable EC integrations;
- misuse Zoho, Google, Google Voice, UniFi, GL.iNet, SMS/modem, or other connected systems.
EC may log and review API, webhook, automation, and integration activity.
18. Security Monitoring and Review
EC may monitor and review activity for security purposes.
Security review may include:
- login activity;
- failed login attempts;
- unusual access patterns;
- unusual exports;
- role changes;
- admin actions;
- API activity;
- automation activity;
- certificate views;
- Terms acceptance events;
- database changes;
- backup changes;
- file/attachment activity;
- suspicious user-agent or IP activity.
EC may preserve relevant records and restrict access while reviewing suspected security issues.
19. Incident Response
If EC detects or suspects a security incident, EC may take steps including:
- suspending accounts;
- revoking sessions;
- rotating credentials;
- disabling API keys;
- preserving logs;
- preserving backups;
- creating forensic copies;
- limiting exports;
- restricting admin routes;
- notifying appropriate parties where required;
- restoring from backups;
- reviewing affected records;
- enforcing EC policies;
- seeking legal relief.
EC may delay disclosure of technical details when disclosure could increase risk, interfere with investigation, expose credentials, or impair system security.
20. User Reporting Duties
Users must promptly report suspected security issues, including:
- lost devices;
- stolen devices;
- lost credentials;
- exposed passwords;
- suspicious login activity;
- unauthorized exports;
- suspicious certificate access;
- missing records;
- altered records;
- phishing;
- malware;
- credential sharing;
- attempted lockout;
- attempted system seizure;
- attempted unauthorized database access.
21. Preservation During Disputes or Trigger Events
During disputes, trigger events, employment changes, access revocations, ownership changes, sale/change-of-control events, or suspected policy violations, EC may preserve logs, backups, certificates, Terms versions, policy versions, emails, database records, audit trails, repositories, and infrastructure records.
Users and companies must not delete, alter, conceal, or interfere with preserved records.
22. Enforcement
Violation of this policy may result in:
- account suspension;
- access revocation;
- credential revocation;
- API revocation;
- automation revocation;
- audit review;
- preservation of evidence;
- management notification;
- legal enforcement;
- injunctive relief;
- recovery of costs or fees where available.
23. Changes to This Policy
Quintin N. Mahan may update this Data Security Policy by publishing a new active version in EC.
The current active version will be displayed through the Legal hub.
Older versions may remain stored in Postgres for audit, evidence, and historical review.
24. Contact / Owner
Employee Center is owned by Quintin N. Mahan.
Legal and policy documents are available from:
/legal
The current Terms and Conditions are available from:
/legal/terms-and-conditions
End of Data Security Policy.