Search SecureTrace

Jump to a file, transfer or page

Policies

The rules the product enforces on every transfer. Changing these changes what users are allowed to do — not what they are asked to remember.

Supplier risk tiers
What each tier entitles a supplier to receive. The tier sets the ceiling on onboarding and at every security review; releasing above a vendor's ceiling needs a recorded ISMS exception — ISO 27001 A.5.19 / A.8.3.
Risk tierCeilingBasis
Tier 1 — StrategicRestrictedLong-term partner under continuous assurance; audited, with design data integral to the engagement
Tier 2 — StandardConfidentialEstablished supplier with periodic review; receives project data but not the full design intent
Tier 3 — LimitedInternalLimited or transactional engagement; receives only what the work strictly requires
ClassificationApprovalMax link lifeMax downloadsWatermarkIdentity check
PublicNone90 daysUnlimitedOptionalOptional
InternalNone30 days10OptionalRecommended
ConfidentialManager14 days5RequiredRequired
RestrictedManager + ISMS on exception7 days3EnforcedEnforced