Skip to content

Physical Security Policy

Authorized By: Head of People

This Policy ensures that Safire, Inc. provides adequate physical and environmental safeguards to prevent damage and unauthorized access to Safire’s Information Systems, information assets, and Nonpublic Information (NPI) as well as other confidential and sensitive data.

This Policy covers all Safire facilities and all Safire information assets regardless of physical locations.

Physical and Environmental Security Policy Safire will prevent unauthorized physical access to, damage to, and interference with Safire’s premises and information assets. Safire will develop and implement processes, procedures, and guidelines for implementing physical and environmental protections

Physical Security Perimeter Safire will design and implement physical security perimeters to protect areas that contain its Information Systems and confidential and sensitive data.

  • Entry to Safire’s premises will be limited to authorized personnel by placing control mechanisms on external doors.
  • Doors to Safire’s internal areas that contain its Information Systems and confidential and sensitive information (e.g., data center, communication closet, etc.) will be adequately secured.
  • Safire will strictly control and limit the distribution of keys or passes (including ID badges, cards/passkeys) used to access secure areas and will frequently review who has such access to ensure that access remains limited to only those individuals who need it.
  • Safire will establish, maintain, and review visitor logs quarterly, and no less frequently than necessary to ensure effectiveness.
  • Visitor access to limited areas will be restricted. Visitors will be escorted, supervised and monitored to ensure they do not access restricted areas or take away any of Safire’s technology or information assets.
  • Safire will design and implement physical protection against damage from fire, water, flood, earthquake, explosion, civil unrest, and other forms of natural or human-made disasters.
  • Emergency procedures will be documented and communicated clearly, and personnel will be trained on what to do in emergencies.
  • Fire detection systems will be installed in accordance with requisite laws and regulations and HVAC systems will be configured to shut down upon fire detection automatically.
  • Safire will conduct risk assessments to identify and remediate any security threats presented by neighboring premises.
  • Information Systems will be located away from hazardous processes or materials.
  • Safire will provide adequate power supplies and auxiliary power supplies to its Information Systems.
  • Safire will adequately protect its Information Systems and any devices with Safire’s information assets against damage from exposure to water, smoke, dust, chemicals, electrical supply interference, etc.
  • Safire will implement adequate controls to prevent the unauthorized removal of equipment.
  • Safire will establish guidelines for eating, drinking, and smoking in the proximity of Information Systems and devices with Safire’s information assets.
  • Physical access to wireless access points, networking and communication hardware, and telecommunication lines will be restricted.
  • A clear desk policy requiring sensitive information, documents, and media to be stored securely in cabinets or away from public view when not in use will be implemented.
  • Sensitive or critical business information will be locked away when not in use and when the office is vacated.
  • Key locks, encryption, passwords, and other controls will be used to prevent unauthorized access to Safire’s data on workstation computers, computer terminals, and other devices used for access to Safire’s network .
  • Unauthorized photography, video, or audio recording of proprietary information, whiteboards, or screens is prohibited within Safire premises.
  • Use of information assets outside of Safire premises is restricted to authorized personnel and company-managed devices in accordance with the Mobile Device Management Policy.
  • Information assets and media taken off the premises will not be left unattended and will be secured at all times.
  • Portable computing devices will be carried on person when traveling (see Safire’s Employee Travel Guide).

The policy owner will verify compliance through methods such as business tool reports and internal and external audits. Oversight is provided by CISO, IT, and Compliance functions. Enforcement of this policy is coordinated through Human Resources and Executive Management.

Any exceptions must be approved by the Policy Owner in advance.

An employee found to have violated this policy may be subject to disciplinary action, up to and including termination of employment.

Section titled “Related Standards, Policies, Plans, and Procedures”
  • Mobile Device Management Policy

  • Employee Travel Guide

Revision History

2026-08-20 — Darren Rush
Merge pull request #2 from safire-dev/dev (16cb681)
Edit this Page