Assurance and scope
Blue Bench Media does not currently represent that it holds a SOC 2 report or ISO 27001 certification. Internal policy documents are not independent audit reports. A provider’s certification applies to its stated scope, not automatically to Blue Bench Media.
The requirements below establish a baseline. Buyers should request implementation evidence for the specific systems and data in their engagement. Completed assessments, tests, and reviews must be described by their actual scope and date.
Required control baseline
| Area | Required practice |
|---|---|
| Accounts & access | Individual accounts, least privilege, MFA for supported external interactive access, secure credential storage, quarterly access review, and prompt removal of unnecessary access. Exceptions require documented mitigation. |
| Devices | Supported operating systems, full-disk encryption, active malware protection, firewall, automatic locking, and restricted administrative use. Personal devices handling business data require the same baseline. |
| Updates & vulnerabilities | Apply security updates within 30 days; expedite critical and actively exploited issues. Maintain an asset inventory, risk register, remediation owner, and verification evidence. |
| Data protection | Encrypted transport and appropriately configured storage encryption, restricted logs and backups, minimized payloads, and documented retention. |
| Development & changes | Review, test, approve, and record production changes; keep rollback procedures. Use synthetic or redacted test data and keep secrets out of source code. |
| People & suppliers | Annual security/privacy training and policy acknowledgment, risk-based screening before access, vendor review before onboarding and every six months for relevant providers. |
| Recovery | Document critical systems and recovery objectives. Exercise recovery and test restoration at least annually; retain the actual results. |
These requirements are informed by small-business risk-management guidance; they are not a claim of NIST certification.
NIST small-business cybersecurity guidance ↗Incident response
Report suspected exposure, account compromise, or a security weakness to info@bluebenchmedia.com with “Security Incident” in the subject. Include the affected website or service, time observed, and a concise description. Do not send passwords, complete lead lists, or sensitive consumer records by ordinary email.
The response standard requires triage, containment, evidence preservation, impact assessment, partner coordination, recovery, and a documented lessons-learned review. Notify affected contracted partners without undue delay and within any agreed deadline. For engagements requiring 48-hour notification, the plan must support that deadline from the applicable awareness trigger; investigation must not postpone initial notice. Consumer and regulator notices follow applicable requirements.
Report a security concernAI and confidentiality
Blue Bench Media uses AI tools in creative development, software development, and productivity workflows. Policy prohibits entering partner confidential information, consumer PII, credentials, or production lead records into an AI service without specific authorization and appropriate safeguards. This restriction also covers automated agent access to files, logs, and connected applications. Human review is required for externally used output.
This trust center’s technical scope
The center is a static HTTPS website on AWS. Its content origin is private, with access through the delivery service. Site assets are served locally; no advertising tags, embedded third-party fonts, or analytics scripts are included. These statements apply to this center, not all campaign websites or the company’s entire device fleet.
Review and documentation
The founder must review this standard annually and after material changes or incidents. Supporting records include an asset inventory, risk register, access review, training record, change log, vendor review, incident log, and recovery-test record. The existence of this policy does not establish a history of completed reviews.
Request engagement-specific documentation →