← Back

EC Data Security Policy

02_legal_root/ec_data_security_policy.md

Employee Center Data Security Policy

No Raw Database Data Claim

For clarity, this document does not claim that Quintin N. Mahan owns raw facts, raw database rows, independent outside source records, CRS-owned operational records, customer-owned records, third-party-owned records, or customer relationships merely because such information is entered into, stored in, processed by, displayed through, backed up with, or exported from EC.

This document protects EC Protected Materials: the application, software, source code, schemas, database design, data model, relationships, indexes, workflows, dashboards, reports, queries, automations, integrations, APIs, access controls, credentials, hardware, infrastructure, legal records, certificate records, hashes, metadata systems, audit systems, methods, processes, techniques, trade secrets, documentation, and EC-created structural organization.

Version: 1.0
Effective Date: June 1, 2026
Platform: Employee Center / EC
Owner: Quintin N. Mahan
Legal Hub: /legal
Policy URL: /legal/data-security-policy


1. Purpose

This Data Security Policy explains how Employee Center (“EC”) protects EC systems, EC accounts, EC data, EC credentials, EC legal records, EC certificates, EC backups, EC audit logs, EC infrastructure, and the EC Protected Materials.

EC is a private operational platform owned by Quintin N. Mahan. Access to EC is conditional, limited, revocable, and governed by the Employee Center Terms and Conditions.

This policy is intended to support confidentiality, integrity, availability, accountability, legal preservation, evidence preservation and authorized transition support, and protection of EC ownership.


2. Scope

This policy applies to:

This policy applies to EC access through browsers, dashboards, APIs, automations, webhooks, scripts, service accounts, database tools, admin tools, terminals, file shares, backups, and connected integrations.


3. Relationship to Other Policies

This policy works together with:

If this Data Security Policy conflicts with the Employee Center Terms and Conditions, the Terms and Conditions control unless Quintin N. Mahan signs a separate written agreement stating otherwise.

Nothing in this policy transfers ownership of EC, EC source code, EC data, EC backups, EC certificates, EC repositories, EC credentials, EC infrastructure, or the EC Protected Materials.


4. Security Principles

EC security is based on these principles:


5. Account Security

Each user is responsible for protecting their EC account.

Users must not:

Users should report suspected account compromise promptly.


6. Passwords, Sessions, and Authentication

EC may use authentication controls to protect access.

These controls may include:

EC may suspend, revoke, expire, or reset sessions, accounts, or credentials where needed for security, enforcement, or preservation.


7. Role-Based Access

EC may restrict access by:

Users may not attempt to access modules, records, reports, dashboards, certificates, exports, admin tools, APIs, or integrations outside their authorized role.


8. Owner/Admin Access

Owner/admin access is required to operate, maintain, secure, preserve, audit, and defend EC.

Quintin N. Mahan may retain owner/admin access to:

No user or company may disable, revoke, seize, transfer, or interfere with owner/admin access except through lawful process.


9. Credentials, Tokens, and Keys

EC credentials must be protected.

Protected credentials include:

Users may not copy, export, disclose, rotate, revoke, reset, or use EC credentials except as authorized by Quintin N. Mahan.


10. Database Security

EC databases may contain operational, customer, employee, audit, legal, certificate, and backup-related records.

Users may not access EC databases directly unless authorized.

Users may not:

Database access may be logged, restricted, monitored, and reviewed.


11. Source Code and Repository Security

EC source code, repositories, deployment files, configuration files, migrations, scripts, automations, templates, certificate generators, report logic, dashboard logic, and integration code are protected EC materials.

Users may not:


12. Backup Security

EC backups may include databases, files, attachments, legal records, Terms versions, policy versions, certificates, generated PDFs, logs, exhibits, configuration, and metadata.

Backups must be protected from unauthorized access, deletion, corruption, seizure, transfer, or lockout.

Users may not:


13. Logging and Audit Security

EC may preserve logs and audit trails for security, troubleshooting, operations, evidence, legal defense, enforcement, and evidence preservation and authorized transition support.

Protected logs may include:

Users may not delete, alter, conceal, disable, or interfere with EC logs or audit trails.


EC legal records are protected EC records.

Protected legal records include:

Users may not alter, delete, forge, backdate, conceal, corrupt, or interfere with EC legal records.


15. Device Security

Users should access EC only from devices that are appropriate for authorized EC work.

Users should not use EC from devices that are:

Users should sign out when finished, especially on shared or portable devices.


16. Network and Infrastructure Security

EC may rely on networks, routers, firewalls, reverse proxies, DNS, Tailscale, VPNs, local networks, cloud networks, storage systems, servers, Raspberry Pis, modems, APIs, and integrations.

Users may not interfere with EC infrastructure or network security.

Users may not:


17. API, Webhook, and Integration Security

EC APIs, webhooks, automations, and integrations must be used only as authorized.

Users may not:

EC may log and review API, webhook, automation, and integration activity.


18. Security Monitoring and Review

EC may monitor and review activity for security purposes.

Security review may include:

EC may preserve relevant records and restrict access while reviewing suspected security issues.


19. Incident Response

If EC detects or suspects a security incident, EC may take steps including:

EC may delay disclosure of technical details when disclosure could increase risk, interfere with investigation, expose credentials, or impair system security.


20. User Reporting Duties

Users must promptly report suspected security issues, including:


21. Preservation During Disputes or Trigger Events

During disputes, trigger events, employment changes, access revocations, ownership changes, sale/change-of-control events, or suspected policy violations, EC may preserve logs, backups, certificates, Terms versions, policy versions, emails, database records, audit trails, repositories, and infrastructure records.

Users and companies must not delete, alter, conceal, or interfere with preserved records.


22. Enforcement

Violation of this policy may result in:


23. Changes to This Policy

Quintin N. Mahan may update this Data Security Policy by publishing a new active version in EC.

The current active version will be displayed through the Legal hub.

Older versions may remain stored in Postgres for audit, evidence, and historical review.


24. Contact / Owner

Employee Center is owned by Quintin N. Mahan.

Legal and policy documents are available from:

/legal

The current Terms and Conditions are available from:

/legal/terms-and-conditions

End of Data Security Policy.