Acceptable Use Policy
This policy sets out what is expected of everyone in the day-to-day use of Bunker's assets (workstations, operational access, internal tooling and the data entrusted by our customers). On that dimension, it implements the principles of our information security policy and covers controls A.5.10, A.6.7, A.7.7 and A.8.1 of the Statement of Applicability.
Our controls are self-assessed, aligned with ISO/IEC 27001, not certified by a third party to date. The status of each measure below reflects that self-assessment. This is the area where our formalisation is least advanced, and we state it plainly.
Purpose and scope
This policy applies to anyone using a Bunker asset (endpoint, account, operational access, internal tool), on our premises or working remotely. What applies to customers of the platform is governed by the terms of use published on the website, not by this page.
Principles
- Assets serve the business: the means provided are there for the role, and residual personal use must never degrade security.
- Credentials are personal: they are not shared, not copied into a third-party tool, and not stored in clear text.
- Operational access goes through the VPN: infrastructure administration goes through the encrypted WireGuard tunnel, never through a directly exposed service.
- Production data stays in production systems: test datasets are synthetic, and no production personal data is copied into a test environment.
- An unattended device is locked: sessions are locked on leaving the desk, and sensitive documents are not left in view.
- Doubt gets reported: a lost device, a suspicious message, an abnormal access, everything is reported immediately rather than investigated alone.
Measures
| Area | Measure |
|---|---|
| Use of assets | Public terms of use and tooling guardrails in place; an internal acceptable-use charter to be documented (A.5.10, partial). |
| Remote working | Operational access through the encrypted WireGuard VPN (Headscale); a remote-working policy to be formalised (A.6.7, partial). |
| Clear desk and clear screen | Good practice applied by the team; a formal policy to be established (A.7.7, planned). |
| User endpoint devices | An endpoint management policy to be formalised (A.8.1, planned). |
| Credentials | Encrypted server-side confidential sessions, no token exposed to the browser; credentials themselves are governed by our access control policy (A.5.17). |
| Test data | Test datasets are synthetic, with no production personal data (A.8.33). |
| Privileged tooling | Strong technical restriction of privileged utilities (rootless builders, reduced-surface images, Pod Security Admission); a usage policy to be formalised (A.8.18, partial). |
Responsibilities
- The CISO (François-Guillaume Ribreau) owns this policy and the forthcoming internal acceptable-use charter and endpoint management policy.
- The DPO (Robin Straub) is involved whenever a use case touches personal data.
- Every user applies these principles and reports any incident, lost device or abnormal access without delay to [email protected].
Status and roadmap
The technical protections framing day-to-day use are in place, namely an encrypted VPN for operational access, confidential sessions, restricted privileged utilities, synthetic test data. What is missing is the documentary side, and we are not dressing it up. Acceptable use of assets (A.5.10) and remote working (A.6.7) are declared partial for want of a written charter, and the clear desk and clear screen policy (A.7.7) and the endpoint management policy (A.8.1) are planned. This page states the principles the charter will formalise; their status will be updated in the Statement of Applicability once the corresponding internal procedures are written and traceably applied.
Review
This policy is reviewed at least once a year and whenever our working tools or our remote-access arrangements change significantly.
Last reviewed: 31 August 2026.
See also
- Statement of Applicability (the status of controls A.5.10, A.6.7, A.7.7 and A.8.1)
- Access Control Policy (the rights opened on the systems these assets reach)
- Human Resources Security Policy (the undertakings made on hiring and on departure)
- Information Security Policy (the ISMS framework this policy derives from)