Security Practices
Data security measures maintained by Town to protect personal data.
This page serves as the Security Annex referenced in Town's Data Processing Addendum.
Last updated: June 2026
Security Annex
What this page covers.
Town maintains a written information security program with technical and organizational measures designed to protect personal data against unauthorized access, use, disclosure, alteration, or destruction.
13 security measures
Organizational, technical, and physical controls that make up Town's information security program.
Living document
Town may update these measures from time to time, provided updates do not materially decrease the overall protection of personal data.
Security measures.
The following measures are maintained as part of Town's information security program.
1
Organizational management
Dedicated staff responsible for the development, implementation, and maintenance of Town's information security program.
2
Audit and risk assessment
Procedures for periodic review and assessment of risks to Town's organization, monitoring and maintaining compliance with Town's policies and procedures, and reporting the condition of its information security and compliance to internal senior management.
3
Data security controls
Logical segregation of data, restricted (e.g., role-based) access and monitoring, and use of commercially available industry-standard encryption technologies for personal data that is transmitted over public networks (i.e., the Internet) or when transmitted wirelessly or at rest or stored on portable or removable media (i.e., laptop computers, CD/DVD, USB drives, back-up tapes).
4
Logical access controls
Controls designed to manage electronic access to data and system functionality based on authority levels and job functions (e.g., granting access on a need-to-know and least-privilege basis, use of unique IDs and passwords for all users, periodic review, and revoking/changing access promptly when employment terminates or changes in job functions occur).
5
Password controls
Controls designed to manage and control password strength, expiration, and usage including prohibiting users from sharing passwords and requiring that passwords assigned to employees: (i) be at least eight (8) characters in length, (ii) not be stored in readable format on computer systems, (iii) have defined complexity, (iv) have a history threshold to prevent reuse of recent passwords, and (v) newly issued passwords must be changed after first use.
6
System audit and event logging
Related monitoring procedures to proactively record user access and system activity.
7
Physical and environmental security
Security of data centers, server room facilities, and other areas containing personal data designed to: (i) protect information assets from unauthorized physical access, (ii) manage, monitor, and log movement of persons into and out of facilities, and (iii) guard against environmental hazards such as heat, fire, and water damage.
8
Operational procedures
Controls to provide for configuration, monitoring, and maintenance of technology and information systems, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from Town's possession.
9
Change management
Procedures and tracking mechanisms designed to test, approve, and monitor all material changes to Town's technology and information assets.
10
Incident management
Procedures designed to allow Town to investigate, respond to, mitigate, and notify of events related to Town's technology and information assets.
11
Network security
Controls that provide for the use of enterprise firewalls and layered DMZ architectures, and intrusion detection systems and other traffic and event correlation procedures designed to protect systems from intrusion and limit the scope of any successful attack.
12
Vulnerability assessment and patch management
Threat protection technologies, and scheduled monitoring procedures designed to identify, assess, mitigate, and protect against identified security threats, viruses, and other malicious code.
13
Business resiliency and disaster recovery
Continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergencies or disasters.
Notes.
Town may update these security measures as its information security program evolves. Any updates will not materially decrease the overall protection of personal data.
These measures describe organizational commitments. For the current list of vendors that process data on Town's behalf, see town.com/subprocessors.
Questions about security?
If your organization needs more detail on our security practices or data handling, we'd love to help.