Optizio Policy Documents

Optizio Information Security Policy

Introduction

This Information Security Policy outlines the principles and procedures that Optizio follows to protect its information assets and customer data, ensuring compliance with UK legal requirements, Shopify’s standards, and industry best practices.

Scope

This policy applies to all Optizio employees, contractors, and third parties who access company systems, data, or networks.

1. Purpose

2. Roles and Responsibilities

3. Information Security Objectives

4. Access Control

5. Data Protection and Privacy

6. Password Policy

Optizio maintains a separate Password Policy document, which is based on the OWASP ASVS 4.0 Section V2.1 Password Security Requirements and is implemented to the fullest extent possible within the capabilities of third-party services.

7. Secure Development Practices

8. Software and System Maintenance

9. Incident Management

10. Training and Awareness

11. Compliance and Audit

12. Policy Review

Contact For questions or to report a security incident, contact: support@optiz.io