Skip to content

Security Policy

Owner Patrick Tolvstein
Version 1.0
Created 2026-06-16
Last reviewed 2026-06-16
Next review 2027-06-16

Password manager

All employees must use Dashlane as their password manager for all work-related accounts. Storing passwords in browsers, notes apps, spreadsheets, or any other tool is not permitted.

  • All work credentials must be saved in Dashlane immediately upon creation
  • The company Dashlane account is provided by the company - do not use a personal Dashlane account for work credentials
  • If you lose access to Dashlane, contact Nikolaj (NVA) or Patrick (PT) immediately

Passwords

  • Always use the highest available password strength - use Dashlane's password generator for all new accounts
  • Minimum length: 8 characters, with a mix of letters, numbers, and symbols
  • Never reuse passwords across accounts
  • Never share passwords via email, Slack, or any other messaging tool - use Dashlane's secure sharing feature instead
  • If you suspect a password has been compromised, change it immediately and notify Nikolaj (NVA) or Patrick (PT)

Two-factor authentication (2FA)

  • 2FA must be enabled on all accounts where it is available - this is mandatory, not optional
  • Store 2FA codes in Dashlane alongside the login so the team is not locked out if someone is unavailable
  • Prefer authenticator app-based 2FA (TOTP) over SMS-based 2FA where possible - SMS is vulnerable to SIM-swapping attacks
  • Never share 2FA codes with anyone, and never approve 2FA prompts you did not initiate yourself

Unexpected 2FA prompts

If you receive a 2FA prompt you did not initiate, deny it immediately and notify Patrick (PT). This may indicate that your credentials have been compromised.


Account hygiene

  • Use a unique email address for each service where possible. Do not share accounts whenever possible.
  • Review and revoke access to unused accounts and integrations regularly
  • Never create work accounts using personal email addresses

Devices

Work devices are managed through Kandji (MDM). This means security policies, FileVault encryption, and recovery keys are handled centrally — you do not need to manage these yourself.

  • Lock your screen whenever you leave your device unattended — automatic lock is enforced via Iru after 5 minutes of inactivity
  • Do not attempt to disable or work around MDM (Iru) policies on your device
  • Do not use work devices for personal activities that could introduce security risks
  • Report lost or stolen devices to Patrick (PT) or Nikolaj (NVA) immediately — remote wipe can be initiated via MDM

Phishing and social engineering

  • Never click links or download attachments from unexpected or suspicious emails - verify with the sender via a separate channel if in doubt
  • Legitimate services will never ask for your password via email or chat
  • If you receive a suspicious message that appears to come from a colleague or internal system, verify via phone or in person before acting on it
  • Report suspected phishing attempts to Patrick (PT) - see Incident Response if an account may have been compromised

Questions

If you are unsure whether something is permitted or how to handle a specific situation, contact Patrick (PT) before acting.