Vendor Policy
Purpose and Scope
Section titled “Purpose and Scope”This Vendor Risk Management Policy establishes guidelines for identifying, assessing, and mitigating risks associated with Code Town, Inc. (D/B/A “Shorebird”)’s engagement of third-party Vendors, including Cloud providers.
This policy applies to all employees involved in selecting, contracting, or managing third-party relationships.
Policy Statements: Our Commitments
Section titled “Policy Statements: Our Commitments”The following policy statements outline how we manage risks associated with third-party relationships to protect our information assets and promote regulatory compliance.
Vendor Risk Management Principles
Section titled “Vendor Risk Management Principles”Shorebird is committed to:
- Conducting due diligence before engaging with third party vendors
- Maintaining a vendor inventory, incl. what data they have access to, what their risk level is and who the account owner from Shorebird’s side is
- Continuously monitoring and reassessing vendor risks throughout the relationship lifecycle
- Maintaining appropriate controls to mitigate identified risks
- Ensuring vendor compliance with applicable laws, regulations, and Shorebird’s policies
Vendor Risk Assessment
Section titled “Vendor Risk Assessment”All potential third parties must undergo a risk assessment before engagement. Vendors that have any of the following will be given higher priority over similar vendors that do not:
- The vendor has an established security program and clear documentation on data management.
- The vendor has a security compliance stance such as SOC2, ISO27001, or similar frameworks.
- The vendor has data segregation controls in place that will isolate our company data from other customers.
- The vendor has a support function and documentation available, including support for data management and deletion.
Cloud Service Providers
Section titled “Cloud Service Providers”Cloud service providers, including Google Cloud Platform and Google Workspace, are managed as vendors under this policy, with the following additional requirements:
- Acquisition: Cloud services that store or process company or customer data are classified as High Risk and must provide evidence of an independent security attestation (ISO 27001 or SOC 2 at minimum).
- Use and management: Shorebird is responsible for the secure configuration and use of cloud services, including access management, data protection, and monitoring, in line with each provider’s shared responsibility model.
- Exit: Before adopting a cloud service, Shorebird confirms that its data can be exported and deleted when the service is discontinued. On exit, data is migrated or retrieved, and its deletion by the provider is confirmed.
Risk Categorization
Section titled “Risk Categorization”Vendors will be categorized based on their risk level:
| Risk level | Description |
|---|---|
| High Risk | Critical to operations or with access to sensitive data |
| Medium Risk | Important but not critical, with limited access to sensitive data |
| Low Risk | Non-critical with no access to sensitive data |
Due Diligence
Section titled “Due Diligence”Due diligence will be conducted proportionate to the risk level of the third party, which may include questionnaires, document reviews, on-site assessments, and third-party audits.
Results of due diligence will be documented and reviewed by appropriate stakeholders.
Contracting and Legal Considerations
Section titled “Contracting and Legal Considerations”All third-party relationships are governed by written contracts. Contracts must include appropriate clauses addressing:
- Service level agreements (SLAs)
- Data protection and confidentiality
- Compliance with applicable laws and regulations
- Termination rights
Third parties must disclose and obtain approval for any subcontractors.
Ongoing Monitoring, Reporting and Escalation
Section titled “Ongoing Monitoring, Reporting and Escalation”Reassessment of risks of high-risk third party vendors are conducted on an annual basis and of medium-risk vendors every two years.
Regular reporting on third-party risk status to senior management is established.
Immediate escalation of significant issues or breaches related to third parties to appropriate management and security teams is required.
Compliance and Enforcement
Section titled “Compliance and Enforcement”Compliance with this policy is mandatory for all employees, contractors, and third parties with access to Shorebird’s data.
In rare cases, business needs, local laws, or regulations may require exceptions. Management will approve any exceptions and define alternative solutions.
Non-compliance may lead to disciplinary action, including termination, as per Shorebird’s policies.
Policy Review and Maintenance
Section titled “Policy Review and Maintenance”This policy will be reviewed annually or when significant changes occur to maintain its continuing suitability, adequacy, and effectiveness.
Reviews must consider changes in the regulatory landscape.